Developer Puts All-in-One Secrets Manager Dopbase Through Rigorous Real-World Testing
A developer independently tested Dopbase, a secrets manager that packages a server, admin UI, REST API, and CLI into a single binary, with no sponsorship or incentive. The tool aims to replace common insecure practices like sharing credentials over Slack or storing them in .env files, without requiring complex infrastructure like Vault or Doppler. Testing involved a clean installation, multi-environment secret management, key rotation, CI token usage, and deliberately crashing the server mid-command. The install script was verified to be a straightforward POSIX script that checks OS architecture, downloads a release from GitHub, and validates it with a SHA-256 checksum before installing. Dopbase stores runtime data including its SQLite database and master key locally under a default user directory, keeping it self-contained on infrastructure the user controls.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in