Enterprise-grade Machine-to-Machine secrets management platform
Status: π v1.0.0-rc9 Released
SecretHub is a secure, reliable, and highly automated secrets management platform designed specifically for Machine-to-Machine (M2M) communication. Built in Elixir with a HashiCorp Vault-like architecture, it eliminates hardcoded credentials through centralized management, dynamic generation, and automatic rotation.
| Feature | Description |
|---|---|
| π mTLS Everywhere | Mutual TLS for all Core-Agent communications with PKI-issued certificates |
| π Dynamic Secrets | Short-lived credentials for PostgreSQL, Redis, and AWS STS |
| π Automatic Rotation | Oban-scheduled zero-downtime secret rotation |
| π Template Rendering | EEx-based secret injection into configuration files |
| π Tamper-Proof Audit | SHA-256 hash-chained logs with HMAC signatures |
| π‘οΈ Vault Seal/Unseal | Shamir's Secret Sharing for master key protection |
| β‘ High Availability | Multi-node deployment with distributed locking |
| π Auto-Unseal | AWS KMS, Azure Key Vault, GCP KMS integrations |
| π¨ Anomaly Detection | Real-time security anomaly detection and alerting |
| π Policy Templates | Pre-built policy templates for common use cases |
SecretHub implements a two-tier architecture with a central Core service and distributed Agents:
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β SecretHub Core β
β βββββββββββββ βββββββββββββ βββββββββββββ βββββββββββββ β
β β PKI β β Policy β β Secret β β Audit β β
β β Engine β β Engine β β Engines β β Logger β β
β β β β β β β β β β
β β β’ Root CA β β β’ JSONB β β β’ Static β β β’ Hash β β
β β β’ Int. CA β β β’ Glob β β β’ Dynamic β β Chain β β
β β β’ CSR β β Match β β β’ Leases β β β’ HMAC β β
β βββββββββββββ βββββββββββββ βββββββββββββ βββββββββββββ β
β β
β βββββββββββββ βββββββββββββ βββββββββββββ βββββββββββββ β
β β AppRole β β Vault β β Anomaly β β Apps β β
β β Auth β β Seal/ β β Detection β β Manager β β
β β β β Unseal β β β β β β
β βββββββββββββ βββββββββββββ βββββββββββββ βββββββββββββ β
β β
β REST API + WebSocket + LiveView Admin β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β mTLS WebSocket
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β SecretHub Agent β
β βββββββββββββ βββββββββββββ βββββββββββββ βββββββββββββ β
β β Bootstrap β βConnection β β Cache β β Sinker β β
β β β β Manager β β Layer β β β β
β β β’ Enroll β β β β β β β’ Atomic β β
β β β’ CSR Gen β β β’ Reconn β β β’ TTL β β Write β β
β β β’ mTLS ID β β β’ Backoff β β β’ LRU β β β’ Reload β β
β βββββββββββββ βββββββββββββ βββββββββββββ βββββββββββββ β
β β
β βββββββββββββ βββββββββββββ βββββββββββββββββββββββββββββ β
β β Template β β Lease β β Unix Domain Socket API β β
β β Renderer β β Renewer β β (for local applications) β β
β βββββββββββββ βββββββββββββ βββββββββββββββββββββββββββββ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β UDS + mTLS
ββββββββββββββββββββββββ
β Applications β
ββββββββββββββββββββββββ
- Enrollment Phase: Host identity discovery β pending enrollment β operator approval β TLS CSR + SSH host-key proof β certificate issuance
- Operational Phase: Core-issued mTLS WebSocket identity β Secret requests β Local caching
- Delivery Phase: EEx template rendering β Atomic file writes β Application reload triggers
- Local Access: Unix Domain Socket API for application secret retrieval
| Layer | Algorithm | Details |
|---|---|---|
| At Rest | AES-256-GCM | Per-secret nonces, 128-bit auth tags |
| Master Key | Shamir's Secret Sharing | Configurable N shares, K threshold |
| Key Derivation | PBKDF2-SHA256 | 100,000 iterations |
βββββββββββββββ pending enrollment βββββββββββββββ
β Agent β ββββββββββββββββββββββββββΆβ Core β
β Enrollment β SSH host public key β Approval β
βββββββββββββββ βββββββββββββββ
β β
β TLS CSR + SSH proof β
β βββββββββββββββββββββββββββββββββββββββββΆ
β β
β Agent client certificate β
β βββββββββββββββββββββββββββββββββββββββββ
β β
βΌ βΌ
βββββββββββββββ Core-issued mTLS WS βββββββββββββββ
β Agent β βββββββββββββββββββββββββΆβ Core β
β Runtime β certificate identity β Runtime β
βββββββββββββββ βββββββββββββββ
- Root CA: Self-signed, RSA-4096 or ECDSA P-384
- Intermediate CA: Root-signed, issues client certificates
- Client Certificates: 1-year validity, auto-renewal 7 days before expiry
- Encrypted storage with versioning
- Oban-scheduled rotation
- Template rendering support
| Engine | Description | Lease Management |
|---|---|---|
| PostgreSQL | Temporary users with VALID UNTIL, custom SQL templates |
Auto-revocation |
| Redis | Dynamic ACL-based credentials | Auto-revocation |
| AWS STS | Temporary IAM credentials via AssumeRole | TTL-based |
- devenv: Install from devenv.sh
- direnv (optional): Install from direnv.net
# Clone the repository
git clone https://github.com/gsmlg-dev/secrethub.git
cd secrethub
# Activate devenv (or use direnv allow)
devenv shell
# Set up the database
db-setup
# Start the development server
serverAvailable at:
- Web UI / Admin Dashboard: http://localhost:4664/admin
- REST API: http://localhost:4664/v1
# Database
db-setup # Create and migrate database
db-reset # Reset database (drop, create, migrate, seed)
# Development
server # Start Phoenix server
console # Start IEx shell with app loaded
# Testing
mix test # Run all tests
mix coveralls.html # Generate coverage report
# Code Quality
quality # Run format, credo, dialyzersecrethub/ # Elixir Umbrella Application
βββ apps/
β βββ secrethub_core/ # Core Business Logic
β β βββ lib/secrethub_core/
β β βββ auth/app_role.ex # AppRole authentication
β β βββ pki/ca.ex # PKI/CA management
β β βββ policies.ex # Policy engine
β β βββ policy_templates.ex # Pre-built policy templates
β β βββ apps.ex # Application management
β β βββ audit.ex # Hash-chained audit logs
β β βββ vault/seal_state.ex # Seal/unseal with Shamir
β β βββ engines/dynamic/ # PostgreSQL, Redis, AWS STS
β β βββ auto_unseal/providers/ # AWS KMS, Azure KV, GCP KMS
β β βββ anomaly_detection.ex # Security anomaly detection
β β βββ alerting.ex # Multi-channel alerting
β β βββ lease_manager.ex # Lease lifecycle
β β βββ rotation_manager.ex # Oban-scheduled rotation
β β
β βββ secrethub_web/ # Phoenix Web Layer
β β βββ lib/secrethub_web_web/
β β βββ controllers/ # REST API endpoints
β β βββ live/admin/ # LiveView admin dashboard
β β βββ channels/ # Agent WebSocket channels
β β βββ plugs/ # Rate limiter, mTLS verification
β β
β βββ secrethub_agent/ # Distributed Agent Daemon
β β βββ lib/secrethub_agent/
β β βββ bootstrap.ex # Legacy AppRole bootstrap guard
β β βββ connection.ex # WebSocket client with reconnect
β β βββ cache.ex # TTL + LRU secret cache
β β βββ sinker.ex # Atomic file writer
β β βββ template_renderer.ex # EEx template engine
β β βββ uds_server.ex # Unix Domain Socket API
β β βββ lease_renewer.ex # Auto lease renewal
β β
β βββ secrethub_shared/ # Shared Code
β βββ lib/secrethub_shared/
β βββ schemas/ # 20+ Ecto schemas
β βββ crypto/ # AES-256-GCM, Shamir
β
βββ config/ # Environment configs
βββ infrastructure/ # IaC
β βββ postgres/ # PostgreSQL init scripts
βββ .github/workflows/ # CI/CD pipelines
| Endpoint | Method | Description |
|---|---|---|
/v1/sys/init |
POST | Initialize vault with Shamir shares |
/v1/sys/seal |
POST | Seal the vault |
/v1/sys/unseal |
POST | Unseal vault with key shares |
/v1/sys/seal-status |
GET | Get vault seal status |
/v1/sys/health |
GET | Health check |
/v1/sys/health/ready |
GET | Kubernetes readiness probe |
/v1/sys/health/live |
GET | Kubernetes liveness probe |
| Endpoint | Method | Description |
|---|---|---|
/v1/auth/approle/login |
POST | AppRole login |
/v1/auth/approle/role |
GET | List all roles |
/v1/auth/approle/role/:role_name |
POST | Create AppRole |
/v1/auth/approle/role/:role_name |
DELETE | Delete AppRole |
/v1/auth/approle/role/:role_name/role-id |
GET | Get Role ID |
/v1/auth/approle/role/:role_name/secret-id |
POST | Generate Secret ID |
| Endpoint | Method | Description |
|---|---|---|
/v1/secrets/:path |
GET | Read secret |
/v1/secrets/:path |
POST | Write secret |
/v1/secrets/:path |
DELETE | Delete secret |
/v1/secrets/dynamic/postgresql/creds/:role |
POST | Generate PostgreSQL credentials |
/v1/secrets/dynamic/redis/creds/:role |
POST | Generate Redis credentials |
/v1/secrets/dynamic/aws/creds/:role |
POST | Generate AWS STS credentials |
| Endpoint | Method | Description |
|---|---|---|
/v1/pki/ca/root/generate |
POST | Generate Root CA |
/v1/pki/ca/intermediate/generate |
POST | Generate Intermediate CA |
/v1/pki/issue |
POST | Issue certificate |
/v1/pki/sign-request |
POST | Sign a CSR |
/v1/pki/certificates |
GET | List certificates |
/v1/pki/certificates/:id |
GET | Get certificate details |
/v1/pki/certificates/:id/revoke |
POST | Revoke certificate |
/v1/pki/app/issue |
POST | Issue app certificate (bootstrap) |
/v1/pki/app/renew |
POST | Renew app certificate |
| Endpoint | Method | Description |
|---|---|---|
/v1/apps |
GET | List applications |
/v1/apps |
POST | Register application |
/v1/apps/:id |
GET | Get application details |
/v1/apps/:id |
PUT | Update application |
/v1/apps/:id |
DELETE | Delete application |
/v1/apps/:id/suspend |
POST | Suspend application |
/v1/apps/:id/activate |
POST | Activate application |
/v1/apps/:id/certificates |
GET | List app certificates |
| Endpoint | Method | Description |
|---|---|---|
/v1/sys/leases |
GET | List active leases |
/v1/sys/leases/stats |
GET | Get lease statistics |
/v1/sys/leases/renew |
POST | Renew a lease |
/v1/sys/leases/revoke |
POST | Revoke a lease |
The LiveView-based admin dashboard (/admin) provides:
- Dashboard: System overview, health metrics, quick stats
- Secrets: Secret browser, version history, bulk operations
- Policies: Policy editor, entity bindings, simulator
- Policy Templates: Pre-built templates for common scenarios
- PKI: Root/Intermediate CA management, certificate issuance
- Certificates: Certificate browser, revocation, renewal
- AppRoles: Role management, secret ID rotation
- Agents: Connected agents, status monitoring, health checks
- Dynamic Engines: PostgreSQL/Redis engine configuration
- Engine Health: Real-time engine status dashboard
- Leases: Active lease management, bulk revocation
- Audit: Log viewer, search, CSV export
- Rotations: Rotation schedules, history, manual triggers
- Templates: Secret template management
- Cluster: Node health, distributed state, deployment status
- Auto-Unseal: KMS provider configuration
- Alerts: Alert rules, notification channels
- Anomalies: Anomaly detection rules, triggered alerts
- Performance: Performance metrics dashboard
SecretHub includes a built-in anomaly detection engine with rules for:
| Rule Type | Description |
|---|---|
| Failed Logins | Detect brute-force authentication attempts |
| Bulk Deletion | Alert on mass secret deletion |
| Unusual Access Time | Detect access outside business hours |
| Mass Secret Access | Alert on abnormal secret read patterns |
| Credential Export Spike | Detect unusual credential generation |
| Rotation Failures | Alert on failed secret rotations |
| Policy Violations | Detect policy bypass attempts |
- Email notifications
- Slack webhooks
- Generic webhooks
- PagerDuty integration
- Opsgenie integration
Pre-built policy templates for common scenarios:
| Template | Description |
|---|---|
business_hours |
Access restricted to business hours (9-5) |
ip_restricted |
Access limited to specific IP ranges |
read_only |
Read-only access to secrets |
emergency_access |
Break-glass emergency access |
dev_environment |
Development environment access |
production_readonly |
Production read-only access |
time_limited |
Time-limited access with expiration |
multi_region |
Multi-region access policies |
Start with the deployment guide for current Core, Agent, and CLI deployment steps. The detailed production runbook and operational checklists live under docs/deployment.
| Artifact | Platforms | Includes |
|---|---|---|
secrethub_core-<tag>-linux-*.tar.gz |
Linux amd64, Linux arm64 | Core + Web + Shared |
secrethub_agent-<tag>-*.tar.gz |
Linux, macOS, FreeBSD | Agent + Shared |
secrethub_agent-<tag>-windows-amd64.zip |
Windows amd64 | Agent + Shared |
secrethub_cli |
Hex.pm package | CLI escript |
docker pull ghcr.io/gsmlg-dev/secrethub/core:v1.0.0-rc9
docker pull ghcr.io/gsmlg-dev/secrethub/core-standalone:v1.0.0-rc9
docker pull ghcr.io/gsmlg-dev/secrethub/agent:v1.0.0-rc9Core with external PostgreSQL:
docker run -d -p 4664:4664 \
-e PHX_SERVER=true \
-e PORT=4664 \
-e PHX_HOST=secrethub.example.com \
-e DATABASE_URL="postgresql://secrethub:password@postgres/secrethub_prod" \
-e SECRET_KEY_BASE="$(openssl rand -base64 48)" \
-e SECRET_HUB_CLUSTER_NODE_ID=core-replica-a \
ghcr.io/gsmlg-dev/secrethub/core:v1.0.0-rc9Agent:
docker run -d \
-e SECRET_HUB_AGENT_CORE_URL="https://secrethub.example.com" \
-v /var/lib/secrethub-agent:/app/.local/state/secrethub/agent \
-v /var/run/secrethub:/var/run/secrethub \
ghcr.io/gsmlg-dev/secrethub/agent:v1.0.0-rc9For production, run migrations before starting Core, expose the trusted Agent mTLS endpoint, and persist Agent state. See docs/deploy.md.
| Service | Required |
|---|---|
| Core | PHX_SERVER=true, DATABASE_URL, SECRET_KEY_BASE, PHX_HOST, SECRET_HUB_CLUSTER_NODE_ID |
| Core trusted Agent endpoint | SECRET_HUB_AGENT_ENDPOINT_SERVER=true, endpoint cert/key/CA paths |
| Core admin mTLS endpoint | SECRET_HUB_ADMIN_ENDPOINT_SERVER=true, endpoint cert/key/client-CA paths, canonical admin certificate fingerprints |
| Agent | SECRET_HUB_AGENT_CORE_URL |
SECRET_HUB_CLUSTER_NODE_ID must be stable across restarts and unique to each
concurrently running Core replica.
- Umbrella project structure with 4 apps
- PostgreSQL 16 with UUID, pgcrypto extensions (Unix socket support)
- AppRole authentication (RoleID/SecretID)
- Full PKI engine (Root CA, Intermediate CA, CSR)
- Vault seal/unseal with Shamir's Secret Sharing
- Policy engine with glob patterns and conditions
- Policy templates for common scenarios
- Tamper-evident audit logging (hash chains + HMAC)
- Dynamic secret engines (PostgreSQL, Redis, AWS STS)
- Auto-unseal providers (AWS KMS, Azure Key Vault, GCP KMS)
- Agent bootstrap and mTLS WebSocket connection
- Secret caching with TTL and LRU eviction
- Template rendering and atomic file writes
- Lease management with auto-renewal
- Oban-scheduled secret rotation
- Application management system
- Anomaly detection engine
- Multi-channel alerting (Email, Slack, PagerDuty, Opsgenie)
- LiveView admin dashboard (20+ pages)
- CI/CD with GitHub Actions
- Multi-arch Docker images (amd64/arm64)
- Production deployment guide and operational runbooks
type(scope): subject
Types: feat, fix, docs, style, refactor, test, chore
Example:
feat(core): implement AWS STS dynamic secret engine
- Add AssumeRole credential generation
- Implement lease management
- Add integration tests
MIT License
- Repository: https://github.com/gsmlg-dev/secrethub
- Latest Release: v1.0.0-rc9
- Deployment Guide: docs/deploy.md
- Docker Images:
ghcr.io/gsmlg-dev/secrethub/core|ghcr.io/gsmlg-dev/secrethub/core-standalone|ghcr.io/gsmlg-dev/secrethub/agent