awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Infisical avatar

Infisical/infisical

0
View on GitHub↗
27,374 stars·1,983 forks·TypeScript·20 viewsinfisical.com↗

Infisical

Infisical is a centralized secrets management platform designed to store, synchronize, and control access to sensitive credentials and configuration data across distributed development, staging, and production environments. It employs client-side encryption to ensure that secrets remain unreadable to the underlying storage infrastructure, while providing a hierarchical permission model to govern both user and machine access.

The platform distinguishes itself through dynamic credential provisioning, which generates short-lived access tokens that are automatically revoked after use. It supports complex security workflows by integrating with external identity providers for federated authentication and offering a reverse tunneling gateway that allows secure access to private network resources without exposing inbound ports. Additionally, the system includes an event-driven audit engine that maintains an immutable record of all configuration changes and access requests to support compliance requirements.

Beyond core secret storage, the platform provides comprehensive orchestration capabilities, including automated secret injection into containerized environments and infrastructure pipelines. It also features integrated public key infrastructure management for the lifecycle of digital certificates and automated scanning to detect hardcoded secrets in source code and CI pipelines.

The platform supports flexible deployment models, allowing teams to either utilize managed cloud services or self-host the infrastructure within their own private networks. It provides a broad ecosystem of SDKs and a command-line interface to facilitate integration across various programming languages and deployment workflows.

Features

  • Secrets Management - Provides a centralized system for storing and managing sensitive application secrets.
  • Identity and Access Management - Provides centralized control over user and machine access through defined roles and permissions.
  • Key Management Services - Securely stores, manages, and controls access to sensitive application secrets.
  • Secret Encryption - Encrypts sensitive data locally before transmission to ensure it remains unreadable to central storage infrastructure.
  • Secret Management Systems - Acts as a centralized repository for securely storing, managing, and synchronizing sensitive credentials across distributed infrastructure.
  • Access Control Models - Manages user and machine access to secrets using a hierarchical permission model based on organizational scope.
  • Access Control Policies - Assigns granular permissions to users and services using role-based rules.
  • Access Management - Governs machine and user authentication to ensure granular control over sensitive data access.
  • Dynamic Credential Provisioning - Generates short-lived credentials on demand through cloud providers and automatically revokes them after use.
  • Dynamic Secret Management - Manages the lifecycle of dynamic secrets including leasing, renewal, and revocation.
  • Machine Identity - Automates secure access for servers and pipelines using cloud-native identity and role-based permissions.
  • PKI Management - Automates certificate authority operations and manages public key infrastructure.
  • Public Key Infrastructures - Provides a comprehensive framework for creating, managing, and revoking digital certificates and public-key encryption assets.
  • Secret Orchestration - Centralizes and orchestrates sensitive credentials to ensure secure access across all environments.
  • Environment Bootstrapping - Automates the initial setup of environments including admin users and machine identities.
  • Infrastructure Orchestration Tools - Automates the injection of secrets and configuration parameters into cloud-native deployment pipelines and application environments.
  • Platform Settings - Manages core platform parameters including encryption keys and authentication secrets for secure operation.
  • Self-Hosted Infrastructure - Supports local deployment to maintain complete control over security and compliance requirements.
  • Secure Gateway Services - Establishes secure reverse tunnels to private network resources without inbound firewall rules.
  • Configuration Orchestration - Automatically injects secrets and environment variables into containerized platforms during deployment.
  • Cryptographic Operations - Executes encryption, decryption, signing, and verification tasks using managed keys.
  • Identity Federation - Delegates authentication to third-party identity services to centralize user management and enforce consistent access policies.
  • Machine Identity Authentication - Establishes secure sessions for accessing secrets by verifying machine identities through cloud-specific credentials.
  • Privileged Access Management - Controls access to sensitive administrative functions and privileged credentials.
  • Public Key Infrastructure - Automates the issuance and lifecycle management of digital certificates for secure service communication.
  • Secret Management - Alternative platform for secret management and configuration.
  • Security and Compliance - Platform for secrets and privileged access management.
  • Infrastructure as Code - Uses automated configuration files to ensure consistent and repeatable cloud infrastructure deployments.
  • Reverse Tunnels - Establishes outbound connections to private network resources to bypass firewall restrictions without inbound port exposure.
  • Identity Provider Connections - Links external identity providers to the platform by providing domain and client credentials to enable authentication.
  • Secret Configuration Management - Manages secret lifecycles including creation, updates, and deletion within project environments.
  • Secret Management Utilities - Exports secrets to local files in various formats for secure configuration management.
  • Secrets Scanning - Automatically detects and alerts on hardcoded secrets in source code and infrastructure.
  • Security Auditing - Maintains immutable records of access requests and configuration changes for regulatory compliance.
  • Audit Logging - Records detailed audit trails of platform actions for security and compliance visibility.
  • SDK Authentication - Establishes secure sessions using universal or directory credentials for SDK operations.
  • Cloud Infrastructure Integrations - Establishes secure connections to cloud infrastructure providers for cross-service communication.
  • Container Orchestration - Runs the application and its dependencies as isolated containers using configuration files.
  • Infrastructure Automation - Provisions cloud resources using automated templates to ensure consistent networking and compute setup.
  • Configuration Syncing - Ensures consistent injection of secrets and environment variables across containerized services.
  • Password Manager Integrations - Establishes secure synchronization links to password management servers for secret retrieval.
  • Secret Lifecycle Operations - Maintains secure configuration data through programmatic secret lifecycle operations.
  • Secret Record Management - Provides builder-pattern interfaces to manage secret keys, values, and metadata.
  • Project Scoping - Organizes work into distinct project containers to isolate security workflows.
  • Quality and Compliance Auditing - Records detailed activity logs to provide visibility into secret access and configuration changes.
  • Database Configurations - Provides structured configuration for connecting to database and cache stores with support for secure encrypted connections.
  • Client Authentication - Establishes secure sessions using multiple credential methods for Java applications.
  • Configuration Templates - Merges secret values into configuration templates to automate the secure generation of environment-specific files.
  • Configuration Templating - Generates configuration files by injecting secret values into custom templates.
  • Cloud Container Deployments - Runs the application on managed container services with production-ready traffic routing.
  • Deployment Scaling - Adjusts infrastructure resources based on expected transaction volume and environment usage requirements.
  • Managed Cloud Services - Offloads infrastructure maintenance and scaling to a hosted service provider.
  • Certificate Management - Issues and retrieves certificate bundles for subscribers within a project.
  • Cloud Authentication Integrations - Attaches cloud authentication settings to machine identities by defining trusted resource names and network ranges.
  • Identity Provider Integrations - Provides API endpoints to permanently remove configured identity provider integrations.
  • Organization Management - Centralizes billing, directory management, and security policy enforcement across the organization.
  • Resource Hierarchies - Defines a hierarchical structure of organizations, projects, and environments for access control.

Star history

Star history chart for infisical/infisicalStar history chart for infisical/infisical

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Infisical

Similar open-source projects, ranked by how many features they share with Infisical.
  • pulumi/pulumipulumi avatar

    pulumi/pulumi

    24,797View on GitHub↗

    Pulumi is an infrastructure-as-code framework that enables the definition, deployment, and management of cloud resources using general-purpose programming languages. It functions as a cloud resource orchestrator that coordinates the lifecycle of heterogeneous infrastructure by executing code to construct dependency graphs and reconciling the desired state against actual cloud environments. The platform distinguishes itself through a language-host runtime bridge that allows developers to use standard programming languages to define infrastructure, rather than relying solely on domain-specific

    Goawsazurecloud
    View on GitHub↗24,797
  • dokploy/dokployDokploy avatar

    Dokploy/dokploy

    34,901View on GitHub↗

    Dokploy is a self-hosted platform-as-a-service designed to simplify the deployment and management of containerized applications and databases. It provides a centralized control plane that decouples administrative management from application workloads, allowing users to oversee infrastructure across multiple server nodes through a unified web interface or a command-line tool. The platform distinguishes itself through an extensive library of pre-configured application templates, enabling the rapid deployment of databases, identity providers, and various productivity or development tools. It sup

    TypeScriptbackendbackupsdatabases
    View on GitHub↗34,901
  • gravitational/teleportgravitational avatar

    gravitational/teleport

    19,863View on GitHub↗

    Teleport is a zero-trust access platform designed to provide secure, identity-based connectivity to servers, databases, and Kubernetes clusters. It functions as a centralized gateway that replaces static credentials with short-lived, identity-bound cryptographic certificates, effectively eliminating the need for traditional VPNs and long-term secret exposure. The platform distinguishes itself by orchestrating access through a unified control plane that maps external identity provider claims to granular, role-based infrastructure permissions. It enforces security through mutual TLS gateways an

    Goauditbastioncertificate
    View on GitHub↗19,863
  • smallstep/clismallstep avatar

    smallstep/cli

    4,255View on GitHub↗

    This project is a command-line tool for managing public key infrastructure and digital identities. It provides a comprehensive suite for X.509 certificate lifecycle management, including the generation, signing, renewal, and revocation of certificates and signing requests. The tool distinguishes itself through specialized security capabilities such as binding cryptographic credentials to TPMs and HSMs for hardware-backed identity attestation. It also provides dedicated support for machine identity security, using short-lived SSH certificates and mTLS to secure non-human workloads. Broad capa

    Gocertificatecryptographyencryption
    View on GitHub↗4,255
See all 30 alternatives to Infisical→

Frequently asked questions

What does infisical/infisical do?

Infisical is a centralized secrets management platform designed to store, synchronize, and control access to sensitive credentials and configuration data across distributed development, staging, and production environments. It employs client-side encryption to ensure that secrets remain unreadable to the underlying storage infrastructure, while providing a hierarchical permission model to govern both user and machine access.

What are the main features of infisical/infisical?

The main features of infisical/infisical are: Secrets Management, Identity and Access Management, Key Management Services, Secret Encryption, Secret Management Systems, Access Control Models, Access Control Policies, Access Management.

What are some open-source alternatives to infisical/infisical?

Open-source alternatives to infisical/infisical include: pulumi/pulumi — Pulumi is an infrastructure-as-code framework that enables the definition, deployment, and management of cloud… dokploy/dokploy — Dokploy is a self-hosted platform-as-a-service designed to simplify the deployment and management of containerized… gravitational/teleport — Teleport is a zero-trust access platform designed to provide secure, identity-based connectivity to servers,… smallstep/cli — This project is a command-line tool for managing public key infrastructure and digital identities. It provides a… boto/boto3 — Boto3 is the AWS SDK for Python, providing a programmatic interface for managing and automating AWS cloud… mozilla/sops — Sops is a secrets encryption tool designed to encrypt and decrypt sensitive values within configuration files. It…