{"id":13741204,"url":"https://github.com/banzaicloud/bank-vaults","last_synced_at":"2025-05-08T21:32:47.286Z","repository":{"id":182146513,"uuid":"667831043","full_name":"banzaicloud/bank-vaults","owner":"banzaicloud","description":"A Vault swiss-army knife: A CLI tool to init, unseal and configure Vault (auth methods, secret engines).","archived":true,"fork":true,"pushed_at":"2023-09-11T11:27:08.000Z","size":23050,"stargazers_count":1,"open_issues_count":0,"forks_count":3,"subscribers_count":1,"default_branch":"main","last_synced_at":"2024-11-08T15:05:51.724Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://bank-vaults.dev","language":"Go","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"bank-vaults/bank-vaults","license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/banzaicloud.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":null}},"created_at":"2023-07-18T11:56:20.000Z","updated_at":"2024-10-25T17:33:58.000Z","dependencies_parsed_at":"2023-07-18T22:35:21.723Z","dependency_job_id":"f64d32a7-ae1d-4e14-8d77-3708662c0759","html_url":"https://github.com/banzaicloud/bank-vaults","commit_stats":{"total_commits":1971,"total_committers":243,"mean_commits":8.11111111111111,"dds":0.5438863521055302,"last_synced_commit":"172cd500575e926658205025c15136ad3d60ce7d"},"previous_names":["banzaicloud/bank-vaults"],"tags_count":100,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/banzaicloud%2Fbank-vaults","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/banzaicloud%2Fbank-vaults/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/banzaicloud%2Fbank-vaults/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/banzaicloud%2Fbank-vaults/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/banzaicloud","download_url":"https://codeload.github.com/banzaicloud/bank-vaults/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":224708940,"owners_count":17356521,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-03T04:00:56.731Z","updated_at":"2024-11-15T11:31:00.167Z","avatar_url":"https://github.com/banzaicloud.png","language":"Go","funding_links":[],"categories":["Repository is obsolete","Kubernetes","Kubernetes Operators"],"sub_categories":["Awesome Operators in the Wild"],"readme":"\u003e [!WARNING]\n\u003e Bank-Vaults has been migrated to a new organization: https://github.com/bank-vaults\n\u003e\n\u003e See [this](https://github.com/orgs/bank-vaults/discussions/2118) post for changes and migration steps.\n\u003e\n\u003e **This project does not receive any more updates. We encourage you to upgrade.**\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"docs/images/logo/bank-vaults-logo-vertical.svg\" width=\"270\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n\n  \u003ca href=\"https://hub.docker.com/r/banzaicloud/bank-vaults/\"\u003e\n    \u003cimg src=\"https://img.shields.io/docker/automated/banzaicloud/bank-vaults.svg\" alt=\"Docker Automated build\"\u003e\n  \u003c/a\u003e\n\n  \u003ca href=\"https://hub.docker.com/r/banzaicloud/bank-vaults/\"\u003e\n    \u003cimg src=\"https://img.shields.io/docker/pulls/banzaicloud/bank-vaults.svg?style=shield\" alt=\"Docker Pulls\"\u003e\n  \u003c/a\u003e\n\n  \u003ca href=\"https://godoc.org/github.com/banzaicloud/bank-vaults\"\u003e\n    \u003cimg src=\"https://godoc.org/github.com/banzaicloud/bank-vaults?status.svg\" alt=\"GoDoc\"\u003e\n  \u003c/a\u003e\n\n  \u003ca href=\"https://circleci.com/gh/banzaicloud/bank-vaults\"\u003e\n    \u003cimg src=\"https://circleci.com/gh/banzaicloud/bank-vaults.svg?style=shield\" alt=\"CircleCI\"\u003e\n  \u003c/a\u003e\n\n  \u003ca href=\"https://goreportcard.com/badge/github.com/banzaicloud/bank-vaults\"\u003e\n    \u003cimg src=\"https://goreportcard.com/badge/github.com/banzaicloud/bank-vaults\" alt=\"Go Report Card\"\u003e\n  \u003c/a\u003e\n\n  \u003ca href=\"https://gitpod.io/#https://github.com/banzaicloud/bank-vaults\"\u003e\n    \u003cimg src=\"https://img.shields.io/badge/Gitpod-Ready--to--Code-blue?logo=gitpod\" alt=\"Gitpod Ready-to-Code\"\u003e\n  \u003c/a\u003e\n\n  \u003ca href=\"https://lgtm.com/projects/g/banzaicloud/bank-vaults/alerts/\"\u003e\n    \u003cimg alt=\"Total alerts\" src=\"https://img.shields.io/lgtm/alerts/g/banzaicloud/bank-vaults.svg?logo=lgtm\u0026logoWidth=18\"/\u003e\n  \u003c/a\u003e\n\n\u003c/p\u003e\n\n*Bank Vaults is a thick, tricky, shifty right with a fast and intense tube for experienced surfers only, located on Mentawai. Think heavy steel doors, secret unlocking combinations and burly guards with smack-down attitude. Watch out for clean-up sets.*\n\n*Bank-Vaults is an umbrella project which provides various tools for Vault to make using and operating Hashicorp Vault easier. It's a wrapper for the official Vault client with automatic token renewal and built-in Kubernetes support, dynamic database credential provider for Golang `database/sql` based clients. It has a CLI tool to automatically initialize, unseal, and configure Vault. It also provides a Kubernetes operator for provisioning, and a mutating webhook for injecting secrets.*\n\n---\n\n**Bank-Vaults** is a core building block of the **[Banzai Cloud Pipeline](https://github.com/banzaicloud/pipeline)** platform. Some of the usage patterns are highlighted through these blog posts:\n\n**Securing Kubernetes deployments with Vault:**\n\n- [Authentication and authorization of Pipeline users with OAuth2 and Vault](https://banzaicloud.com/blog/oauth2-vault/)\n- [Dynamic credentials with Vault using Kubernetes Service Accounts](https://banzaicloud.com/blog/vault-dynamic-secrets/)\n- [Dynamic SSH with Vault and Pipeline](https://banzaicloud.com/blog/vault-dynamic-ssh/)\n- [Secure Kubernetes Deployments with Vault and Pipeline](https://banzaicloud.com/blog/hashicorp-guest-post/)\n- [Vault Operator](https://banzaicloud.com/blog/vault-operator/)\n- [Vault unseal flow with KMS](https://banzaicloud.com/blog/vault-unsealing/)\n- [Monitoring Vault on Kubernetes using Cloud Native technologies](https://banzaicloud.com/blog/monitoring-vault-grafana/)\n- [Inject secrets directly into pods from Vault](https://banzaicloud.com/blog/inject-secrets-into-pods-vault-revisited/)\n- [Backing up Vault with Velero](https://banzaicloud.com/blog/vault-backup-velero/)\n- [Vault replication across multiple datacenters on Kubernetes](https://banzaicloud.com/blog/vault-multi-datacenter/)\n- [More blog posts about Bank-Vaults](https://banzaicloud.com/tags/bank-vaults/)\n\nWe use Vault across our large Kubernetes deployments and all the projects were `reinventing` the wheel. We have externalized all the codebase into this project and removed all the [Pipeline](https://github.com/banzaicloud/pipeline) and [Hollowtrees](https://github.com/banzaicloud/hollowtrees) dependencies thus this project can be used independently as a CLI tool to manage Vault, a Golang library to build upon (OAuth2 tokens, K8s auth, Vault operator, dynamic secrets, cloud credential storage, etc), Helm chart for a HA cluster, operator, mutating webhook and a collection of scripts to support some advanced features (dynamic SSH, etc).\n\n\u003eWe take bank-vaults' security and our users' trust very seriously. If you believe you have found a security issue in bank-vaults, please contact us at security@banzaicloud.com.\n\nBank-Vaults is a core part of [Banzai Cloud Pipeline](https://github.com/banzaicloud/pipeline), a Cloud Native application and devops platform that natively supports multi- and hybrid-cloud deployments.\n\n## Supported Kubernetes and Vault versions\n\nThis project aims to support the [latest supported Vault image versions](https://hub.docker.com/_/vault), and three Kubernetes minor versions excluding the latest one.\n\n## Installing\n\nYou usually don't need to use the CLI directly, rather you should install the charts and create Vault instances with the operator and use the webhook inside Kubernetes to mutate Kubernetes resources.\n\nTo grab the `bank-vaults` and `vault-env` CLI binaries go to the [releases](https://github.com/banzaicloud/bank-vaults/releases) page and download them.\n\n## Documentation\n\nRead more about the usage of bank-vaults in the [detailed\nBank-Vaults documentation](https://banzaicloud.com/docs/bank-vaults/) and in our [blog posts about Bank-Vaults](https://banzaicloud.com/tags/bank-vaults/).\n\n## Development\n\nIf you want to hack with bank-vaults please follow the [development\ndocumentation](https://banzaicloud.com/docs/bank-vaults/contributing/).\n\n## Bank-Vaults Support\n\nIf you encounter any problems that is not addressed in our documentation, [open an issue](https://github.com/banzaicloud/bank-vaults/issues) or talk to us on the [Banzai Cloud Slack channel #Bank-Vaults](https://banzaicloud.com/invite-slack/).\n\nIf you find this project useful, help us:\n\n- Support the development of this project and star this repo! :star:\n- If you use Bank-Vaults in a production environment, add yourself to the list of production [adopters](https://github.com/banzaicloud/bank-vaults/blob/main/ADOPTERS.md).:metal: \u003cbr\u003e\n- Help new users with issues they may encounter :muscle:\n- Send a pull request with your new features and bug fixes :rocket:\n\n### Engineering Blog\n\nTo be up-to-date with Bank-Vaults and the other open source and commercial [products of Banzai Cloud, read our blog](https://banzaicloud.com/blog/).\n\n## Credits\n\nKudos to HashiCorp for open sourcing Vault and making secret management easier and more secure.\n\n## License\n\nCopyright (c) 2017-2021 [Banzai Cloud, Inc.](https://banzaicloud.com)\n\nLicensed under the Apache License, Version 2.0 (the \"License\");\nyou may not use this file except in compliance with the License.\nYou may obtain a copy of the License at\n\n[http://www.apache.org/licenses/LICENSE-2.0](http://www.apache.org/licenses/LICENSE-2.0)\n\nUnless required by applicable law or agreed to in writing, software\ndistributed under the License is distributed on an \"AS IS\" BASIS,\nWITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\nSee the License for the specific language governing permissions and\nlimitations under the License.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbanzaicloud%2Fbank-vaults","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbanzaicloud%2Fbank-vaults","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbanzaicloud%2Fbank-vaults/lists"}