Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another alternative developed for AWS deployments, written in Python and uses KMS: Credstash https://github.com/fugue/credstash


The only downside of credstash is that it doesn't have the ability to restrict sets of credentials to different IAM roles. The access is all-or-nothing, per dynamo table.

Otherwise the general design of credstash is very similar to Confidant.


It is possible to use fine grained access control with dynamodb in order to restrict access within a ddb table




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: