You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Bank-Vaults aims to help developers and SREs alike by covering the entire secret management pipeline from operating a secret store to injecting and using secrets in applications.
Org repo URL (provide if all repos under the org are in scope of the application)
The roadmap is still being defined. We are talking to users to figure out their needs and prioritize new features. We already have a number of items on the roadmap, but most of the effort is still going into the project migration from the banzaicloud GitHub organization.
One important goal for the near future is to broaden the scope of the project and add support for other secret management solutions than Hashicorp’s Vault.
If the project is accepted, I agree the project will follow the CNCF IP Policy
Trademark and accounts
If the project is accepted, I agree to donate all project trademarks and accounts to the CNCF
Why CNCF?
The CNCF hosts a vibrant and diverse community of developers and organizations. Contributing to this ecosystem allows the Bank-Vaults to attract more contributors, leading to better and faster improvements. Furthermore, the CNCF is able to provide a vendor neutral home for the project, allowing for collaboration among various vendors, fostering the creation of a solution that delivers collective benefits to all stakeholders within the ecosystem.
Benefit to the Landscape
Bank-Vaults is a well-known solution in the Cloud Native ecosystem. It’s been around longer than most of the competing projects (in fact, Bank-Vaults served as an inspiration for some of them). When looking at secret management solutions in the Cloud Native ecosystem (particularly Kubernetes), Bank-Vaults represents one of the established models for application secret management.
Cloud Native 'Fit'
Bank-Vaults best fits under the Security & Compliance category.
Cloud Native 'Integration'
The project does not depend on any CNCF projects per se. It uses various libraries (for example from Kubernetes). It primarily depends on Hashicorp Vault at the moment.
Cloud Native Overlap
There is no strong overlap with existing solutions. There are other secret management solutions in the CNCF landscape (for example External Secrets Operator), but it takes a fundamentally different approach to managing secrets. Also, Bank-Vaults has a much broader scope (for example has an operator for managing Vault on Kubernetes in addition to managing secret injection).
Similar projects
The aforementioned External Secrets Operator is what’s closest within the CNCF.
DoiT has a secrets-init component that’s basically a fork of the Vault secrets webhook implementing the same functionality for AWS and GCP secret managers (something that we also plan to add):
Application contact emails
mark.sagikazar@gmail.com, team@bank-vaults.dev, ospo@cisco.com
Project Summary
Bank-Vaults is a set of tools covering many aspects of secret management in the Cloud Native ecosystem.
Project Description
Bank-Vaults is an umbrella project for Cloud Native secret management tools:
Bank-Vaults aims to help developers and SREs alike by covering the entire secret management pipeline from operating a secret store to injecting and using secrets in applications.
Org repo URL (provide if all repos under the org are in scope of the application)
https://github.com/bank-vaults
Project repo URL in scope of application
https://github.com/bank-vaults/bank-vaults
Additional repos in scope of the application
https://github.com/bank-vaults/vault-operator
https://github.com/bank-vaults/vault-secrets-webhook
https://github.com/bank-vaults/vault-sdk
https://github.com/bank-vaults/vault-helm-chart
Website URL
https://bank-vaults.dev
Roadmap
Roadmap
Roadmap context
The roadmap is still being defined. We are talking to users to figure out their needs and prioritize new features. We already have a number of items on the roadmap, but most of the effort is still going into the project migration from the banzaicloud GitHub organization.
One important goal for the near future is to broaden the scope of the project and add support for other secret management solutions than Hashicorp’s Vault.
Contributing Guide
https://bank-vaults.dev/docs/contributing/
Code of Conduct (CoC)
https://bank-vaults.dev/docs/code-of-conduct/
Adopters
https://github.com/bank-vaults/bank-vaults/blob/main/ADOPTERS.md
Contributing or Sponsoring Org
https://opensource.cisco.com
Maintainers file
https://github.com/bank-vaults/bank-vaults/blob/main/MAINTAINERS.md
IP Policy
Trademark and accounts
Why CNCF?
The CNCF hosts a vibrant and diverse community of developers and organizations. Contributing to this ecosystem allows the Bank-Vaults to attract more contributors, leading to better and faster improvements. Furthermore, the CNCF is able to provide a vendor neutral home for the project, allowing for collaboration among various vendors, fostering the creation of a solution that delivers collective benefits to all stakeholders within the ecosystem.
Benefit to the Landscape
Bank-Vaults is a well-known solution in the Cloud Native ecosystem. It’s been around longer than most of the competing projects (in fact, Bank-Vaults served as an inspiration for some of them). When looking at secret management solutions in the Cloud Native ecosystem (particularly Kubernetes), Bank-Vaults represents one of the established models for application secret management.
Cloud Native 'Fit'
Bank-Vaults best fits under the Security & Compliance category.
Cloud Native 'Integration'
The project does not depend on any CNCF projects per se. It uses various libraries (for example from Kubernetes). It primarily depends on Hashicorp Vault at the moment.
Cloud Native Overlap
There is no strong overlap with existing solutions. There are other secret management solutions in the CNCF landscape (for example External Secrets Operator), but it takes a fundamentally different approach to managing secrets. Also, Bank-Vaults has a much broader scope (for example has an operator for managing Vault on Kubernetes in addition to managing secret injection).
Similar projects
The aforementioned External Secrets Operator is what’s closest within the CNCF.
DoiT has a secrets-init component that’s basically a fork of the Vault secrets webhook implementing the same functionality for AWS and GCP secret managers (something that we also plan to add):
https://github.com/doitintl/secrets-init
https://github.com/doitintl/kube-secrets-init
(It’s basically unmaintained at this point)
Another tool based on Bank-Vaults’ webhook: https://github.com/innovia/secrets-consumer-webhook
Another similar tool (basically unmaintained): https://github.com/OT-CONTAINER-KIT/k8s-vault-webhook
Landscape
No
Business Product or Service to Project separation
N/A
Project presentations
Automating secret rotation in Kubernetes:
https://fosdem.org/2023/schedule/event/container_kubernetes_secret_rotation/
Automate Secret Rotation in Kubernetes, Then Get Out of the Way!:
https://www.youtube.com/watch?v=NTdyznb6Lc4
Project champions
@sagikazarmark
@justaugustus
Additional information
No response