Skip to content
This repository has been archived by the owner on Nov 22, 2023. It is now read-only.
/ keysync Public archive

Keysync periodically downloads secrets from Keywhiz


Notifications You must be signed in to change notification settings


Repository files navigation


As of 9/18/23 this project is now deprecated and no longer maintained; we recommend using HashiCorp Vault as a more robust and actively supported alternative.


license report

Keysync is a production-ready program for accessing secrets in Keywhiz.

It is a replacement for the now-deprecated FUSE-based keywhiz-fs.

Getting Started


Keysync must be built with Go 1.11+. You can build keysync from source:

$ git clone
$ cd keysync
$ go build

This will generate a binary called ./keysync


Keysync uses Go modules to manage dependencies. If you've cloned the repo into GOPATH, you should export GO111MODULE=on before running any go commands. All deps should be automatically fetched when using go build and go test. Add go mod tidy before committing.


Entire test suite:

go test ./...

Short, unit tests only:

go test -short ./...

Running locally

Keysync requires access to Keywhiz to work properly. Assuming you run Keywhiz locally on default port (4444), you can start keysync with:

./keysync --config keysync-config.yaml