Fetches secrets from Azure Key Vault and weaves them into a convenient .env file
Find a file
2024-03-05 11:47:11 +01:00
.github chore(deps): update azure/login action to v2 2024-03-04 09:46:33 +00:00
bicep chore(deps): update resource microsoft.resources/resourcegroups to 2023-07-01 2023-12-01 14:50:20 +00:00
src feat: consolidate error handling 2023-12-12 15:10:14 +01:00
tests feat: test multiple jobs 2023-11-25 19:55:13 +01:00
.gitignore feat: ignore .env files 2023-11-06 00:38:39 +01:00
Cargo.lock Update keyweave version to 0.2.6 2024-03-05 11:41:24 +01:00
Cargo.toml feat: bump version to 0.2.6 2024-03-05 11:28:31 +01:00
CODE_OF_CONDUCT.md feat: add code of conduct document 2024-01-10 15:41:47 +01:00
LICENSE feat: added author and package information 2023-11-06 00:38:05 +01:00
README.md feat: add tests and branch specific status 2024-03-05 10:47:54 +01:00
SECURITY.md feat: add security document 2024-01-10 15:41:58 +01:00

Keyweave

github crates.io docs.rs build status test status

Keyweave

Keyweave is an open-source tool crafted to seamlessly fetch secrets from Azure Key Vault and weave them into a convenient .env file. Developed in Rust, Keyweave stands out for its efficiency and user-friendly design, making it an ideal choice for managing your application's secrets.

Features

  • Fetch Secrets: Retrieve secrets securely from Azure Key Vault.
  • Filtering: Optionally filter the secrets to be retrieved by name.
  • Output Customization: Choose the name of the output file, defaulting to .env.
  • Azure Default Credentials: Utilizes Azure default credentials for authentication.

Prerequisites

Before diving into Keyweave, ensure you have the following prerequisites:

  • Logged into the right Azure tenant:

    az login --tenant "your-tenant-guid"
    
  • The identity you logged in with has Get and List Secret Permissions in the Access Policies of the Key Vault.

Installation

Cargo

Keyweave is built with Cargo, the Rust package manager. It can also be used to install from crates.io:

cargo install keyweave

Homebrew (MacOS, Linux)

For MacOS and Linux systems, installation is a breeze with Homebrew. Simply run:

brew tap bartvdbraak/keyweave
brew install keyweave

Manual Download

If you prefer manual installation or need binaries for different platforms (including an executable for Windows), visit the Releases page of this GitHub repository.

Invoke-WebRequest -Uri 'https://github.com/bartvdbraak/keyweave/releases/latest/download/keyweave.exe' -OutFile 'keyweave.exe'

Building from Source

To build Keyweave from source, follow these steps:

git clone https://github.com/bartvdbraak/keyweave.git
cd keyweave
cargo build --release

Once built, run Keyweave using Cargo:

cargo run -- --vault-name <VAULT_NAME> [--output <FILE>] [--filter <FILTER>]

Usage

With the binary on your PATH, run Keyweave as follows:

keyweave --vault-name <VAULT_NAME> [--output <FILE>] [--filter <FILTER>]
  • --vault-name <VAULT_NAME>: Sets the name of the Azure Key Vault.
  • --output <FILE>: (Optional) Sets the name of the output file (default: .env).
  • --filter <FILTER>: (Optional) Filters the secrets to be retrieved by name.

Example

keyweave --vault-name my-key-vault --output my-env-file.env --filter my-secret

Documentation

Additional documentation for this package can be found on docs.rs.

License

Keyweave is licensed under the GPLv3 License. See LICENSE for more details.

Contributing

We welcome contributions! Feel free to submit pull requests, report issues, or suggest new features. Your input helps make Keyweave even better.