Infisical is an open-source platform for secrets management, certificate/PKI lifecycle, key management, and privileged access management. Features include a dashboard, CLI, SDKs and API, secret syncs and rotation, leak scanning, a Kubernetes operator, and self-hosting via Docker.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONTerraform provider for managing SAP Cloud Identity Services resources via infrastructure-as-code, with OpenTofu compatibility.
Curated knowledge repository of SRE practices, tools, and culture from leading tech organizations including Airbnb, Netflix, Google, and many others.
Caddy is an extensible, multi-platform web server written in Go that provides automatic HTTPS by default and supports HTTP/1.1, HTTP/2, and HTTP/3.
TerraSecure is an ML-powered security scanner for Terraform and HCL Infrastructure as Code across AWS, Azure, and GCP. It detects cloud misconfigurations at build time using a multi-cloud rule engine, an XGBoost ML model for AWS, and AI analysis for contextual remediation, integrating with CI/CD workflows.
TruffleHog is a Go-based CLI that scans Git, GitHub, GitLab, Docker, S3, GCS, filesystems, CI logs and other sources for leaked credentials; it classifies, verifies and analyzes secrets, with JSON/SARIF output.
Microsandbox runs untrusted workloads in fast, local microVMs with hardware isolation. Supports Docker-like workflows, instant startup, and embeddable SDKs for AI agents, CI jobs, and automation across Linux, macOS, and Windows.
Self-hosted GitHub App that publishes a required check accepting human CODEOWNER approval or approval from explicitly enrolled GitHub Apps, with organization and repository policies; pre-release and shadow-mode only.
Cilium is an eBPF-based networking, security, and observability solution for Kubernetes. It offers CNI networking, identity-based L3-L7 policies, distributed load balancing that can replace kube-proxy, multi-cluster Cluster Mesh, service mesh with mutual authentication, and Hubble observability. It is a CNCF Graduated project with Apache 2.0-licensed user space code.