About this project
Terracreds is a credential helper for Terraform Automation and Collaboration Software. It stores API tokens and other secrets securely in the operating system's credential vault or through third-party vault providers, removing the need to keep secrets in plain-text configuration files.
Supported operating systems include Windows (Credential Manager), macOS (Keychain), and Linux (gnome-keyring). Supported vault providers are AWS Secrets Manager, Azure Key Vault, Google Secret Manager, and HashiCorp Vault. Supported Terraform platforms include env0, Scalr, Spacelift, Terraform Cloud, and Terraform Enterprise.
Installation is available through Chocolatey on Windows, Homebrew on macOS and Linux, or by downloading binaries from GitHub releases. The project can also be built from source with Go. The `terracreds generate` command creates the plugin binary and directory that Terraform recognizes, and can optionally create a Terraform CLI configuration file with the credentials_helper block.
Credentials can be stored through the standard `terraform login` flow or manually with `terracreds create`. Other commands support getting, updating, deleting, and listing credentials. The list command can output values as Terraform variables or JSON. Configuration commands generate settings for each supported vault provider.
Terracreds adds protection by associating a username with stored credentials and denying access to users other than the creator. Logging can be enabled through configuration or the `terracreds config logging` command. The README documents troubleshooting for public registry authentication and Linux gnome-keyring issues.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.