fnox
Encrypted/remote secret manager
...It can store secrets encrypted in Git through providers such as age, AWS KMS, Azure KMS, and GCP KMS, or reference secrets stored remotely in services like AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, 1Password, Bitwarden, Infisical, and HashiCorp Vault. Projects define their secret behavior in a fnox.toml file, which can contain encrypted values, provider references, defaults, and environment-specific profiles. Commands can be run with secrets loaded through fnox exec, or users can enable shell integration to load secrets when entering a project directory. The project is designed to avoid vendor lock-in while supporting real-world development, staging, and production differences. ...