{"id":32792625,"url":"https://github.com/jdx/fnox","last_synced_at":"2026-06-12T18:00:58.211Z","repository":{"id":319773064,"uuid":"1078762196","full_name":"jdx/fnox","owner":"jdx","description":"encrypted/remote secret manager","archived":false,"fork":false,"pushed_at":"2026-06-11T21:03:33.000Z","size":2768,"stargazers_count":1821,"open_issues_count":8,"forks_count":88,"subscribers_count":6,"default_branch":"main","last_synced_at":"2026-06-11T23:06:37.824Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://fnox.jdx.dev","language":"Rust","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jdx.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null},"funding":{"github":"jdx","custom":"https://en.dev"}},"created_at":"2025-10-18T11:19:04.000Z","updated_at":"2026-06-11T20:55:54.000Z","dependencies_parsed_at":"2026-05-14T23:03:25.513Z","dependency_job_id":"fdf93065-3e3a-43b7-aa5b-152b0c450343","html_url":"https://github.com/jdx/fnox","commit_stats":null,"previous_names":["jdx/fnox"],"tags_count":47,"template":false,"template_full_name":null,"purl":"pkg:github/jdx/fnox","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jdx%2Ffnox","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jdx%2Ffnox/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jdx%2Ffnox/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jdx%2Ffnox/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jdx","download_url":"https://codeload.github.com/jdx/fnox/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jdx%2Ffnox/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34256188,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-12T02:00:06.859Z","response_time":109,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-11-05T16:02:25.066Z","updated_at":"2026-06-12T18:00:58.205Z","avatar_url":"https://github.com/jdx.png","language":"Rust","funding_links":["https://github.com/sponsors/jdx","https://en.dev"],"categories":["Rust","Secret Management","others"],"sub_categories":[],"readme":"# 🔐 fnox\n\n**Fort Knox for your secrets.**\n\n[![CI](https://github.com/jdx/fnox/actions/workflows/ci.yml/badge.svg)](https://github.com/jdx/fnox/actions/workflows/ci.yml)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n\nManage secrets with encryption or cloud providers—or both! fnox gives you a unified interface to work with secrets across development, CI, and production.\n\n## Sponsors\n\nfnox is sponsored by [37signals](https://37signals.com).\n\n## Quick Start\n\n```bash\n# Install via mise (recommended)\nmise use -g fnox\n\n# Initialize in your project\nfnox init\n\n# Set a secret (encrypted by default)\nfnox set DATABASE_URL \"postgresql://localhost/mydb\"\n\n# Get a secret\nfnox get DATABASE_URL\n\n# Run commands with secrets loaded\nfnox exec -- npm start\n\n# Enable shell integration (auto-load on cd)\neval \"$(fnox activate bash)\"  # or zsh, fish — see docs for Nushell\n```\n\n## What is fnox?\n\nfnox lets you store secrets in two ways:\n\n1. **Encrypted in git** - Using age, AWS KMS, Azure KMS, or GCP KMS\n2. **Remote in cloud** - Using AWS Secrets Manager, AWS Parameter Store, Azure Key Vault, GCP Secret Manager, 1Password, Bitwarden, Bitwarden Secrets Manager, Infisical, or HashiCorp Vault\n\nYour `fnox.toml` config file either contains encrypted secrets or references to remote secrets. Use `fnox exec` to run commands with secrets loaded, or enable shell integration to auto-load secrets when you `cd` into a directory.\n\n## Supported Providers\n\n### 🔐 Encryption (secrets in git, encrypted)\n\n- [**age**](https://fnox.jdx.dev/providers/age) - Modern encryption (works with SSH keys!)\n- [**aws-kms**](https://fnox.jdx.dev/providers/aws-kms) - AWS Key Management Service\n- [**azure-kms**](https://fnox.jdx.dev/providers/azure-kms) - Azure Key Vault encryption\n- [**gcp-kms**](https://fnox.jdx.dev/providers/gcp-kms) - Google Cloud KMS\n\n### ☁️ Cloud Secret Storage (remote, centralized)\n\n- [**aws-ps**](https://fnox.jdx.dev/providers/aws-ps) - AWS Parameter Store\n- [**aws-sm**](https://fnox.jdx.dev/providers/aws-sm) - AWS Secrets Manager\n- [**azure-sm**](https://fnox.jdx.dev/providers/azure-sm) - Azure Key Vault Secrets\n- [**gcp-sm**](https://fnox.jdx.dev/providers/gcp-sm) - Google Cloud Secret Manager\n- [**bitwarden-sm**](https://fnox.jdx.dev/providers/bitwarden-sm) - Bitwarden Secrets Manager\n- [**vault**](https://fnox.jdx.dev/providers/vault) - HashiCorp Vault\n\n### 🔑 Password Managers \u0026 Secret Services\n\n- [**1password**](https://fnox.jdx.dev/providers/1password) - 1Password CLI\n- [**bitwarden**](https://fnox.jdx.dev/providers/bitwarden) - Bitwarden/Vaultwarden\n- [**infisical**](https://fnox.jdx.dev/providers/infisical) - Infisical secrets management\n\n### 💻 Local Storage\n\n- [**keychain**](https://fnox.jdx.dev/providers/keychain) - OS Keychain (macOS/Windows/Linux)\n- [**keepass**](https://fnox.jdx.dev/providers/keepass) - KeePass database files (.kdbx)\n- [**password-store**](https://fnox.jdx.dev/providers/password-store) - GPG-encrypted password store (Unix pass)\n- [**plain**](https://fnox.jdx.dev/providers/plain) - Plain text (for defaults only!)\n\n## Documentation\n\n**📚 [Complete Documentation](https://fnox.jdx.dev/)**\n\n### Quick Links\n\n- [Installation](https://fnox.jdx.dev/guide/installation)\n- [Quick Start Guide](https://fnox.jdx.dev/guide/quick-start)\n- [How It Works](https://fnox.jdx.dev/guide/how-it-works)\n- [Shell Integration](https://fnox.jdx.dev/guide/shell-integration)\n- [Providers Overview](https://fnox.jdx.dev/providers/overview)\n- [Real-World Example](https://fnox.jdx.dev/guide/real-world-example)\n\n### Provider Guides\n\n- [Age Encryption](https://fnox.jdx.dev/providers/age) - Simple, free, works with SSH keys\n- [AWS Secrets Manager](https://fnox.jdx.dev/providers/aws-sm) - Centralized AWS secret management\n- [AWS Parameter Store](https://fnox.jdx.dev/providers/aws-ps) - Simple, cost-effective AWS secret storage\n- [1Password](https://fnox.jdx.dev/providers/1password) - Integrate with 1Password CLI\n- [Bitwarden](https://fnox.jdx.dev/providers/bitwarden) - Open source password manager\n\n[**View all providers →**](https://fnox.jdx.dev/providers/overview)\n\n### Reference\n\n- [CLI Reference](https://fnox.jdx.dev/cli/)\n- [Environment Variables](https://fnox.jdx.dev/reference/environment)\n- [Configuration File](https://fnox.jdx.dev/reference/configuration)\n\n## Example\n\n```toml\n# fnox.toml\n\n[providers]\nage = { type = \"age\", recipients = [\"age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p\"] }\n\n[secrets]\n# Development secrets (encrypted in git)\nDATABASE_URL = { provider = \"age\", value = \"YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNjcnlwdC...\" }  # ← encrypted, safe to commit\nAPI_KEY = { default = \"dev-key-12345\" }  # ← plain default for local dev\n\n[profiles.production.providers]\naws = { type = \"aws-sm\", region = \"us-east-1\", prefix = \"myapp/\" }\n\n[profiles.production.secrets]\nDATABASE_URL = { provider = \"aws\", value = \"database-url\" }  # ← reference to AWS secret\n```\n\n```bash\n# Development (uses encrypted secrets)\nfnox exec -- npm start\n\n# Production (uses AWS Secrets Manager)\nfnox exec --profile production -- ./deploy.sh\n```\n\n## Why fnox?\n\n- **Flexible** - Mix and match encryption and cloud providers\n- **Team-friendly** - Encrypted secrets in git, everyone can decrypt\n- **Multi-environment** - Different providers for dev, staging, prod\n- **Shell integration** - Auto-load secrets on directory change\n- **Developer-focused** - Simple config, powerful features\n- **No vendor lock-in** - Switch providers anytime\n\n## Installation\n\n### Using mise (recommended)\n\n```bash\nmise use -g fnox\n```\n\n### Using Cargo\n\n```bash\ncargo install fnox\n```\n\n### From Source\n\n```bash\ngit clone https://github.com/jdx/fnox\ncd fnox\ncargo install --path .\n```\n\n## Development\n\nSee [CLAUDE.md](./CLAUDE.md) for development guidelines.\n\n```bash\n# Build\nmise run build\n\n# Run tests\nmise run test\n\n# Run specific tests\nmise run test:cargo\nmise run test:bats\n\n# Lint\nmise run lint\n\n# Full CI check\nmise run ci\n```\n\n## License\n\nMIT License - see [LICENSE](LICENSE) for details.\n\n## Links\n\n- [Documentation](https://fnox.jdx.dev/)\n- [GitHub Repository](https://github.com/jdx/fnox)\n- [Issue Tracker](https://github.com/jdx/fnox/issues)\n- [mise](https://mise.jdx.dev) - Recommended installation method\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjdx%2Ffnox","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjdx%2Ffnox","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjdx%2Ffnox/lists"}