awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

11 repositorios

Awesome GitHub RepositoriesDynamic Credential Provisioning

Automated generation and revocation of short-lived credentials on demand.

Distinguishing note: Focuses on the lifecycle management of temporary credentials, distinct from static secret storage.

Explore 11 awesome GitHub repositories matching security & cryptography · Dynamic Credential Provisioning. Refine with filters or upvote what's useful.

Awesome Dynamic Credential Provisioning GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • hashicorp/vaultAvatar de hashicorp

    hashicorp/vault

    35,796Ver en GitHub↗

    Vault is a centralized secrets management platform designed to secure, store, and control access to sensitive credentials such as API keys, passwords, certificates, and encryption keys. At its core, the system employs a barrier-based cryptographic sealing mechanism that requires an unseal process to decrypt internal storage, ensuring that sensitive data remains protected. It provides identity-based access control to manage granular permissions across distributed infrastructure, effectively centralizing security policies and authentication for both human and machine workloads. What distinguish

    Generates short-lived, automatically rotated credentials to minimize the impact of potential security breaches.

    Gogosecretsvault
    Ver en GitHub↗35,796
  • infisical/infisicalAvatar de Infisical

    Infisical/infisical

    27,374Ver en GitHub↗

    Infisical is a centralized secrets management platform designed to store, synchronize, and control access to sensitive credentials and configuration data across distributed development, staging, and production environments. It employs client-side encryption to ensure that secrets remain unreadable to the underlying storage infrastructure, while providing a hierarchical permission model to govern both user and machine access. The platform distinguishes itself through dynamic credential provisioning, which generates short-lived access tokens that are automatically revoked after use. It supports

    Generates short-lived credentials on demand through cloud providers and automatically revokes them after use.

    TypeScriptacmecertificate-managementcli
    Ver en GitHub↗27,374
  • pulumi/pulumiAvatar de pulumi

    pulumi/pulumi

    24,797Ver en GitHub↗

    Pulumi is an infrastructure-as-code framework that enables the definition, deployment, and management of cloud resources using general-purpose programming languages. It functions as a cloud resource orchestrator that coordinates the lifecycle of heterogeneous infrastructure by executing code to construct dependency graphs and reconciling the desired state against actual cloud environments. The platform distinguishes itself through a language-host runtime bridge that allows developers to use standard programming languages to define infrastructure, rather than relying solely on domain-specific

    Issues short-lived, just-in-time credentials via OIDC that automatically expire to eliminate risks associated with static access keys.

    Goawsazurecloud
    Ver en GitHub↗24,797
  • fosrl/pangolinAvatar de fosrl

    fosrl/pangolin

    21,255Ver en GitHub↗

    Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n

    Exchanges long-lived tokens for unique host identifiers and secrets during initial connection to eliminate manual pre-configuration.

    TypeScriptcrowdsecdockerhome-lab
    Ver en GitHub↗21,255
  • project-chip/connectedhomeipAvatar de project-chip

    project-chip/connectedhomeip

    8,586Ver en GitHub↗

    This project is an open-source software development kit and framework for implementing the Matter smart home standard. It provides a universal IPv6-based application layer and a cluster-based data model to ensure interoperability between diverse smart home devices and controllers. The system is distinguished by its multi-transport network abstraction, which maps Bluetooth LE, Thread, and Wi-Fi implementations to a common layer. It includes specialized tooling for secure device commissioning via QR codes and NFC, as well as a comprehensive over-the-air firmware update system for distributing s

    Sends Thread or Wi-Fi credentials from a controller to a device to enable local network joining.

    C++build-with-matterchipconnected-devices
    Ver en GitHub↗8,586
  • tzapu/wifimanagerAvatar de tzapu

    tzapu/WiFiManager

    7,210Ver en GitHub↗

    WiFiManager is a captive portal and web server framework used for configuring wireless credentials and network settings on ESP8266 microcontrollers. It provides an embedded network configuration interface that allows users to connect devices to a wireless network via a web browser rather than hardcoding credentials. The system functions by temporarily acting as a wireless host and redirecting incoming web requests to a local configuration page. It distinguishes itself through a customizable portal that supports user-defined input parameters, visual themes, and multi-language localization to c

    Connecting an ESP8266 device to a wireless network by entering credentials through a web browser instead of hardcoding them.

    C++arduinocaptiveconfiguration-portal
    Ver en GitHub↗7,210
  • alibaba/alios-thingsAvatar de alibaba

    alibaba/AliOS-Things

    4,620Ver en GitHub↗

    AliOS-Things is a scalable operating system for internet-connected devices. It provides an embedded firmware framework and runtime for managing hardware peripherals, network connectivity, and secure data execution across diverse CPU architectures. The system includes an edge AI inference engine for processing audio and image patterns locally without cloud dependencies. It also features a cloud connectivity SDK for automated onboarding, remote diagnostics, and log reporting, alongside a scripting engine for executing high-level code on resource-constrained hardware. Connectivity is handled th

    Handles network configuration and provisioning, including Bluetooth-based setup for internet connectivity.

    C
    Ver en GitHub↗4,620
  • blinker-iot/blinker-esp-idfAvatar de blinker-iot

    blinker-iot/blinker-esp-idf

    4,246Ver en GitHub↗

    Este proyecto es un SDK de integración en la nube IoT y una biblioteca C++ diseñada para conectar hardware ESP32 a un servicio de gestión remota. Proporciona un puente de comunicación que permite el intercambio de datos bidireccional en tiempo real entre dispositivos embebidos y clientes remotos. La biblioteca utiliza un modelo de comunicación de relé en la nube y autenticación de dispositivos basada en claves para asegurar la conexión entre el hardware y la nube. Incluye una herramienta de aprovisionamiento dedicada para transferir de forma segura las credenciales de red inalámbrica a los dispositivos durante la configuración inicial. El framework se integra directamente con el entorno de desarrollo ESP-IDF para gestionar los recursos de hardware y la conectividad inalámbrica. Admite capacidades de servidor WebSocket y manejo de eventos asíncronos para procesar mensajes de red y disparadores de hardware.

    Implements a secure handshake process to transfer wireless network credentials to the device during setup.

    C
    Ver en GitHub↗4,246
  • blynk-technologies/blynk-libraryAvatar de Blynk-Technologies

    Blynk-Technologies/blynk-library

    3,971Ver en GitHub↗

    Blynk es un framework de dispositivos embebidos y biblioteca de conectividad IoT en la nube diseñada para establecer una comunicación segura y bidireccional entre microcontroladores y una plataforma de gestión remota. Proporciona la identidad central de una herramienta de gestión de dispositivos IoT, permitiendo la sincronización de estados de dispositivos, control remoto de hardware y el mapeo de datos de hardware a interfaces basadas en la nube. El proyecto se distingue por un sistema de pines virtuales que desacopla la comunicación en la nube de los pines físicos, permitiendo el intercambio de datos independiente del hardware. También admite la descarga de arquitectura avanzada, donde la comunicación de red puede delegarse a un coprocesador dedicado para admitir microcontroladores no conectados. La biblioteca cubre una amplia gama de capacidades, incluyendo aprovisionamiento automatizado de dispositivos, actualizaciones de firmware over-the-air y una estructura organizativa multi-inquilino para la gestión de flotas. Integra varios protocolos de comunicación como MQTT y HTTPS, y proporciona herramientas para la automatización basada en lógica, almacenamiento de datos de series temporales y la construcción de dashboards móviles y web para monitoreo en tiempo real. El proyecto está implementado en C++.

    Enables secure transfer of WiFi credentials and device identifiers from a mobile app to hardware.

    C++arduinocellularembedded
    Ver en GitHub↗3,971
  • raspberrypi/pico-examplesAvatar de raspberrypi

    raspberrypi/pico-examples

    3,835Ver en GitHub↗

    This project is a reference library of firmware examples and a development framework for creating embedded C applications on the RP2040 microcontroller. It provides a collection of hardware peripheral drivers and foundational patterns for managing system resources in resource-constrained environments. The library features reference implementations for programmable I/O state machines, allowing for the creation of custom hardware-level protocols. It also provides a multicore embedded framework to distribute computational workloads across multiple processor cores using symmetric processing. The

    Provides a mechanism to collect and save Wi-Fi credentials using a temporary access point and web page.

    C
    Ver en GitHub↗3,835
  • boostport/kubernetes-vaultAvatar de Boostport

    Boostport/kubernetes-vault

    937Ver en GitHub↗

    Este proyecto es un controlador de Kubernetes que automatiza la recuperación e inyección de secretos desde HashiCorp Vault en cargas de trabajo en contenedores. Al operar como un bucle de control, monitorea el estado del clúster para entregar datos de configuración sensibles y tokens de autenticación directamente en los entornos de aplicación, eliminando el requisito de credenciales estáticas. El sistema se distingue por un mecanismo de inyección basado en sidecar que intercepta eventos del ciclo de vida de los pods para montar secretos en tiempo de ejecución. Admite el aprovisionamiento dinámico de credenciales, generando tokens de corta duración bajo demanda para reducir los riesgos de seguridad asociados con las claves de acceso a largo plazo. Para garantizar la fiabilidad operativa, el controlador mantiene una alta disponibilidad en múltiples instancias utilizando replicación de estado basada en consenso y descubrimiento automático de pares. La plataforma incluye características integrales de seguridad y observabilidad, como autenticación TLS mutua para comunicación interna y gestión de tráfico cifrado. También proporciona soporte integrado para monitoreo al exponer datos de rendimiento operativo a través de endpoints autenticados compatibles con herramientas de análisis externas.

    Generates short-lived authentication tokens on demand to replace static credentials and reduce long-term access risks.

    Gokubernetesvault
    Ver en GitHub↗937
  1. Home
  2. Security & Cryptography
  3. Dynamic Credential Provisioning

Explorar subetiquetas

  • Network Credential ProvisioningThe secure transfer of Wi-Fi or Thread network credentials from a controller to a new device. **Distinct from Dynamic Credential Provisioning:** Distinct from Dynamic Credential Provisioning: focuses on the initial transfer of network access keys rather than short-lived session tokens.