{"id":35631990,"url":"https://github.com/netresearch/t3x-nr-vault","last_synced_at":"2026-04-22T01:07:23.774Z","repository":{"id":330841200,"uuid":"1124082336","full_name":"netresearch/t3x-nr-vault","owner":"netresearch","description":"Secure secrets management for TYPO3 with envelope encryption, access control, and audit logging","archived":false,"fork":false,"pushed_at":"2026-04-16T21:25:41.000Z","size":2249,"stargazers_count":2,"open_issues_count":1,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-04-16T23:25:43.934Z","etag":null,"topics":["typo3-extension"],"latest_commit_sha":null,"homepage":"","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/netresearch.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null}},"created_at":"2025-12-28T09:41:02.000Z","updated_at":"2026-04-16T21:25:46.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/netresearch/t3x-nr-vault","commit_stats":null,"previous_names":["netresearch/t3x-nr-vault"],"tags_count":13,"template":false,"template_full_name":null,"purl":"pkg:github/netresearch/t3x-nr-vault","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/netresearch%2Ft3x-nr-vault","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/netresearch%2Ft3x-nr-vault/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/netresearch%2Ft3x-nr-vault/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/netresearch%2Ft3x-nr-vault/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/netresearch","download_url":"https://codeload.github.com/netresearch/t3x-nr-vault/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/netresearch%2Ft3x-nr-vault/sbom","scorecard":{"id":1241832,"data":{"date":"2026-01-12T21:50:13Z","repo":{"name":"github.com/netresearch/t3x-nr-vault","commit":"9194f9e8bbc1678f37aa772f7632d8d278bc40ee"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":6,"checks":[{"name":"Maintained","score":0,"reason":"project was created within the last 90 days. Please review its contents carefully","details":["Warn: Repository was created within the last 90 days."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1","Info: detected update tool: RenovateBot: renovate.json:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy"}},{"name":"Code-Review","score":0,"reason":"Found 1/28 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/slsa-provenance.yml:14","Info: jobLevel 'actions' permission set to 'read': .github/workflows/slsa-provenance.yml:115","Warn: topLevel 'contents' permission set to 'write': .github/workflows/auto-merge-deps.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/pr-quality.yml:9","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release.yml:9","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/security.yml:12","Info: topLevel permissions set to 'read-all': .github/workflows/slsa-provenance.yml:7","Info: topLevel 'contents' permission set to 'read': .github/workflows/tests.yml:18","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":9,"reason":"dependency not pinned by hash detected -- score normalized to 9","details":["Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: .ddev/web-build/Dockerfile:15-254","Warn: third-party GitHubAction not pinned by hash: .github/workflows/slsa-provenance.yml:118: update your workflow using https://app.stepsecurity.io/secureworkflow/netresearch/t3x-nr-vault/slsa-provenance.yml/main?enable=pin","Warn: containerImage not pinned by hash: .ddev/web-build/Dockerfile:2","Info:  22 out of  22 GitHub-owned GitHubAction dependencies pinned","Info:  19 out of  20 third-party GitHubAction dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.3.0 not signed: https://api.github.com/repos/netresearch/t3x-nr-vault/releases/275862442","Warn: release artifact v0.2.0 not signed: https://api.github.com/repos/netresearch/t3x-nr-vault/releases/275569624","Warn: release artifact v0.1.1 not signed: https://api.github.com/repos/netresearch/t3x-nr-vault/releases/275209673","Warn: release artifact v0.3.0 does not have provenance: https://api.github.com/repos/netresearch/t3x-nr-vault/releases/275862442","Warn: release artifact v0.2.0 does not have provenance: https://api.github.com/repos/netresearch/t3x-nr-vault/releases/275569624","Warn: release artifact v0.1.1 does not have provenance: https://api.github.com/repos/netresearch/t3x-nr-vault/releases/275209673"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases"}},{"name":"CII-Best-Practices","score":7,"reason":"badge detected: Silver","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: GNU General Public License v2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: all commits (3) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast"}},{"name":"CI-Tests","score":10,"reason":"2 out of 2 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests"}},{"name":"Contributors","score":6,"reason":"project has 2 contributing companies or organizations -- score normalized to 6","details":["Info: found contributions from: netresearch, oroinc"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors"}}]},"last_synced_at":"2026-01-17T06:30:47.539Z","repository_id":330841200,"created_at":"2026-01-17T06:30:47.539Z","updated_at":"2026-01-17T06:30:47.539Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32116514,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-22T00:31:26.853Z","status":"ssl_error","status_checked_at":"2026-04-22T00:30:22.894Z","response_time":128,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["typo3-extension"],"created_at":"2026-01-05T09:14:34.266Z","updated_at":"2026-04-22T01:07:23.767Z","avatar_url":"https://github.com/netresearch.png","language":"PHP","funding_links":[],"categories":[],"sub_categories":[],"readme":"# nr-vault: Secure Secrets Management for TYPO3\n\n[![CI](https://github.com/netresearch/t3x-nr-vault/actions/workflows/ci.yml/badge.svg)](https://github.com/netresearch/t3x-nr-vault/actions/workflows/ci.yml)\n[![codecov](https://codecov.io/gh/netresearch/t3x-nr-vault/graph/badge.svg)](https://codecov.io/gh/netresearch/t3x-nr-vault)\n[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/netresearch/t3x-nr-vault/badge)](https://securityscorecards.dev/viewer/?uri=github.com/netresearch/t3x-nr-vault)\n[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/11695/badge)](https://www.bestpractices.dev/projects/11695)\n[![TYPO3](https://img.shields.io/badge/TYPO3-13.4%20|%2014-orange.svg)](https://typo3.org/)\n[![PHP](https://img.shields.io/badge/PHP-8.2+-blue.svg)](https://www.php.net/)\n[![PHPStan](https://img.shields.io/badge/PHPStan-level%2010-brightgreen.svg)](https://phpstan.org/)\n[![License](https://img.shields.io/badge/License-GPL--2.0--or--later-blue.svg)](LICENSE)\n[![Latest Release](https://img.shields.io/github/v/release/netresearch/t3x-nr-vault)](https://github.com/netresearch/t3x-nr-vault/releases)\n[![Contributor Covenant](https://img.shields.io/badge/Contributor%20Covenant-3.0-4baaaa.svg)](CODE_OF_CONDUCT.md)\n[![SLSA 3](https://slsa.dev/images/gh-badge-level3.svg)](https://slsa.dev)\n\n*Enterprise-grade secret management without enterprise-grade complexity.*\n\n## The Problem\n\nYour TYPO3 site integrates with Stripe, SendGrid, Google Maps, and a dozen other services. **Where are those API keys right now?**\n\nProbably in plain text in `LocalConfiguration.php`, unencrypted in a database field, or hardcoded somewhere accessible to every backend user.\n\nIf your database leaks, your secrets leak. If you need to rotate a compromised key, you're editing config files and redeploying.\n\n## How Secrets Are Typically Stored\n\n| Method | Security | Operational Reality |\n|--------|----------|---------------------|\n| **External Services** (HashiCorp Vault, AWS SM) | ⭐⭐⭐⭐⭐ | Infrastructure cost, network access, auth to service |\n| **Environment Variables** | ⭐⭐⭐ | Deployment/host access required, restart to change, **no rotation UI, no audit trail** |\n| **Files outside webroot** | ⭐⭐⭐ | Deployment/host access required, **hard to rotate, no management interface** |\n| **nr-vault (encrypted DB)** | ⭐⭐⭐⭐ | Runtime manageable via TYPO3 backend, rotate anytime, full audit trail |\n| **Plain text in config/DB** | ⭐ | ❌ No protection |\n\n## Why nr-vault?\n\nAll \"more secure\" methods require either external infrastructure, deployment pipelines, or server access. And they all lack a management UI and audit trail.\n\n| Challenge | Env Vars / Files | nr-vault |\n|-----------|------------------|----------|\n| **Rotate a compromised API key** | Call DevOps, redeploy, restart | Click in backend, done |\n| **See who accessed a secret** | Check deploy logs (if any) | Full audit log with timestamps |\n| **Emergency credential revocation** | Wait for deployment pipeline | Immediate via backend module |\n| **Non-technical editor updates SMTP password** | Create support ticket | Self-service in backend |\n| **Compliance audit: prove access history** | Manually correlate logs | Export tamper-evident audit trail |\n\n## Solution\n\nnr-vault provides:\n\n- **Envelope encryption** with AES-256-GCM via libsodium\n- **Master key management** (file, environment variable, or derived)\n- **Per-secret access control** via backend user groups with context scoping\n- **Audit logging** of all secret access with tamper-evident hash chain\n- **Key rotation** support for both secrets and master key\n- **TCA integration** via custom `vaultSecret` field type\n- **Vault HTTP Client** - make authenticated API calls without exposing secrets\n- **CLI commands** for DevOps automation\n- **Pluggable adapter architecture** (external vault adapters planned for future releases)\n\n## Architecture\n\n```mermaid\nflowchart TB\n    subgraph TYPO3[\"TYPO3 Backend\"]\n        subgraph Entry[\"Entry Points\"]\n            TCA[\"TCA Field\u003cbr/\u003e(vaultSecret)\"]\n            Backend[\"Backend Module\u003cbr/\u003e(Secrets Manager)\"]\n            CLI[\"CLI Commands\"]\n        end\n\n        TCA \u0026 Backend \u0026 CLI --\u003e VaultService\n\n        subgraph VaultService[\"VaultService\"]\n            API[\"store() | retrieve() | rotate() | delete() | list() | http()\"]\n        end\n\n        VaultService --\u003e AccessControl[\"AccessControl\u003cbr/\u003eService\"]\n        VaultService --\u003e Encryption[\"EncryptionService\"]\n        VaultService --\u003e Audit[\"AuditLogService\"]\n\n        Encryption --\u003e Adapters\n\n        subgraph Adapters[\"Vault Adapters\"]\n            Local[\"LocalDatabase\u003cbr/\u003e(DEFAULT)\"]\n            Future[\"Future: HashiCorp,\u003cbr/\u003eAWS, Azure\"]\n        end\n    end\n```\n\n## Encryption Model\n\nUses **envelope encryption** (same pattern as AWS KMS, Google Cloud KMS):\n\n```mermaid\nflowchart TB\n    MK[\"🔐 Master Key\u003cbr/\u003e(stored outside database)\"]\n    DEK[\"🔑 Data Encryption Key (DEK)\u003cbr/\u003e(unique per secret)\"]\n    Secret[\"📄 Secret Value\u003cbr/\u003e(API key, password, token)\"]\n\n    MK --\u003e|encrypts| DEK\n    DEK --\u003e|encrypts| Secret\n```\n\nBenefits:\n- Master key rotation only requires re-encrypting DEKs (fast)\n- Each secret has unique encryption\n- Compromise of one secret doesn't expose others\n\n## Quick Start\n\n### Store and Retrieve Secrets\n\n```php\nuse Netresearch\\NrVault\\Service\\VaultServiceInterface;\n\nclass MyService\n{\n    public function __construct(\n        private readonly VaultServiceInterface $vault,\n    ) {}\n\n    public function storeApiKey(string $provider, string $apiKey): void\n    {\n        $this-\u003evault-\u003estore(\n            identifier: \"my_extension_{$provider}_api_key\",\n            secret: $apiKey,\n            options: [\n                'owner' =\u003e $GLOBALS['BE_USER']-\u003euser['uid'],\n                'groups' =\u003e [1, 2],  // Admin, Editor groups\n                'context' =\u003e 'payment',  // Permission scoping\n                'expiresAt' =\u003e time() + 86400 * 90,  // 90 days\n            ]\n        );\n    }\n\n    public function getApiKey(string $provider): ?string\n    {\n        return $this-\u003evault-\u003eretrieve(\"my_extension_{$provider}_api_key\");\n    }\n}\n```\n\n### Vault HTTP Client\n\nMake authenticated API calls without exposing secrets to your code:\n\n```php\nuse GuzzleHttp\\Psr7\\Request;\nuse Netresearch\\NrVault\\Http\\SecretPlacement;\nuse Netresearch\\NrVault\\Http\\VaultHttpClientInterface;\n\nclass PaymentService\n{\n    public function __construct(\n        private readonly VaultHttpClientInterface $httpClient,\n    ) {}\n\n    public function chargeCustomer(array $payload): array\n    {\n        // Configure vault-based authentication (returns a new immutable client)\n        $client = $this-\u003ehttpClient-\u003ewithAuthentication('stripe_api_key', SecretPlacement::Bearer);\n\n        // Send a standard PSR-7 request - the secret is injected automatically\n        $request = new Request(\n            'POST',\n            'https://api.stripe.com/v1/charges',\n            ['Content-Type' =\u003e 'application/json'],\n            json_encode($payload),\n        );\n        $response = $client-\u003esendRequest($request);\n\n        return json_decode($response-\u003egetBody()-\u003egetContents(), true);\n    }\n}\n```\n\nSecret placement options: `Bearer`, `BasicAuth`, `Header`, `QueryParam`, `BodyField`, `ApiKey`, `OAuth2`.\n\n## TCA Integration\n\n```php\n'api_key' =\u003e [\n    'label' =\u003e 'API Key',\n    'config' =\u003e [\n        'type' =\u003e 'input',\n        'renderType' =\u003e 'vaultSecret',\n        'size' =\u003e 30,\n    ],\n],\n```\n\n## CLI Commands\n\n```bash\n# Initialize vault (create master key)\nvendor/bin/typo3 vault:init\n\n# List secrets (respects access control)\nvendor/bin/typo3 vault:list\n\n# Rotate a secret\nvendor/bin/typo3 vault:rotate my_secret_id --reason=\"Scheduled rotation\"\n\n# Rotate master key (re-encrypts all DEKs)\nvendor/bin/typo3 vault:rotate-master-key --new-key=/path/to/new.key --confirm\n\n# View audit log\nvendor/bin/typo3 vault:audit --identifier=my_secret_id --days=30\n```\n\n## Requirements\n\n- **TYPO3**: v13.4 / v14.0+\n- **PHP**: ^8.2\n- **Extensions**: `ext-sodium` (bundled with PHP)\n- **CPU**: AES-NI support recommended (XChaCha20-Poly1305 fallback available)\n\n## Documentation\n\nFull documentation is available in the `Documentation/` folder and can be rendered with the TYPO3 documentation tools.\n\n### Render locally\n\n```bash\ndocker run --rm -v $(pwd):/project ghcr.io/typo3-documentation/render-guides:latest --progress Documentation\n# Open Documentation-GENERATED-temp/Index.html\n```\n\n### Planning documents\n\nInternal development documents are available in `docs/`:\n\n- [Architecture](docs/architecture.md) - System architecture overview\n- [API Reference](docs/api.md) - Service API documentation\n- [Database Schema](docs/database.md) - Database structure\n- [Security Considerations](docs/security.md) - Security design decisions\n- [Use Cases](docs/use-cases.md) - Supported use cases\n\n## Feature Comparison\n\n| Feature | nr-vault | Drupal Key | Laravel Secrets | Symfony Secrets |\n|---------|----------|------------|-----------------|-----------------|\n| Envelope encryption | Yes | No | No | No |\n| Per-secret DEKs | Yes | No | No | No |\n| External vault support | Planned | Pluggable | Limited | HashiCorp |\n| Access control | BE groups + context | By key | N/A | N/A |\n| Audit logging | Full + hash chain | Limited | None | None |\n| TCA/Form integration | Native | Form API | N/A | N/A |\n| Key rotation CLI | Yes | Manual | Yes | Yes |\n| HTTP client | Yes | No | No | No |\n| OAuth auto-refresh | Yes | No | No | No |\n\n## Roadmap\n\n- **Phase 1-5**: Core functionality (current focus)\n- **Phase 6**: External adapters (HashiCorp, AWS, Azure) + Optional Rust FFI for zero-PHP-exposure\n- **Phase 7**: Service Registry - abstract away both credentials AND endpoints\n\n## Installation\n\n```bash\ncomposer require netresearch/nr-vault\n```\n\nOr in DDEV:\n\n```bash\nddev start\nddev install-v14\nddev vault-init\n```\n\n## License\n\nGPL-2.0-or-later\n\n---\n\n**[n]** Developed by [Netresearch DTT GmbH](https://www.netresearch.de/) - Enterprise TYPO3 Solutions\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnetresearch%2Ft3x-nr-vault","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnetresearch%2Ft3x-nr-vault","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnetresearch%2Ft3x-nr-vault/lists"}