Hey Product Hunt ๐,
We're super excited to launch the new and improved Phase! ๐ฅ๐ฅ
Phase is an easy-to-use application secrets manager for developers. Instead of hard-coding secrets into your code or using .env files and sharing them over Slack.
๐ฉ Simply import your existing secrets into Phase via the CLI by running: phase secrets import .env
๐ Then inject them into your application at runtime by running: phase run node index.js
๐ This keeps your secrets secure and always in sync with your teammates across dev, staging, and prod environments.
๐๏ธ Phase also integrates with other tools and services you may be using, such as GitHub, Docker, Kubernetes, and AWS. Phase will automatically deploy your secrets and configs to these services, giving you a single source of truth across your team and infrastructure.
๐ We take the complexity out of securing your secrets by using end-to-end encryption, audit logging, role-based access policies, and IP whitelisting.
๐ฉโ๐ป We believe in shifting security left and providing an uncompromised, seamless developer experience โ something we found lacking in existing tools like HashiCorp Vault or AWS Secrets Manager.
We're excited for all of you to try it! โค๏ธ
Check out our GitHub: https://github.com/phasehq/console
Join our Slack community: https://slack.phase.dev
Hey @nimishk, this is a great tool. When you work with a distributed team it is always a real pain to share secrets and credentials. I also love the fact that you offer a self-hosted version. Especially in Europe a lot of companies insist on hosting on premise ๐
Congrats on the launch! ๐
Hey @jerriclynsjohn ๐
Infisical is great. I think you will find a significant improvement in DX with Phase, as well as a more thorough and considered approach to the security model. We also have a wider vision of application security that we want to expand into beyond just application secrets!
I would love something like this for SSH keys. Maybe with local encryption and decryption on demand with some other key, like a smart card or something like that.
Hey @m_dolr ๐
We have focused primarily on developer experience and reducing friction to let developers focus on what they do best: build and ship code! Phase is security-focused developer tool, but we believe that developer tools should ease developer productivity first and foremost, and that this will inherently drive adoption and improve security in an organization.
We've also built Phase on a sophisticated end-to-end encryption architecture that we have built from the ground up for the unique requirements of secrets management in teams of all sizes. You can find out more about that on our docs: https://docs.phase.dev/security/...
Congratulations @nimishk on launching Phase! This looks like a game changer for managing application secrets. The end-to-end encryption and seamless integrations with tools like GitHub and AWS will definitely help teams streamline their workflows. Excited to try it out! ๐
๐ Congratulations on launching the new and improved Phase! ๐ฅ
๐ Phase is a crucial tool for securely managing and deploying application secrets. Importing secrets via CLI and injecting them at runtime ensures security and synchronization across environments. How does Phase handle integrations with tools like GitHub, Docker, and Kubernetes while maintaining a single source of truth?
๐๏ธ Integration with services like AWS, alongside seamless developer experience, is impressive. How do Phase's end-to-end encryption and role-based access policies work together to keep secrets secure?
๐ ๏ธ Automated deployment of secrets and configs is a great feature. How does Phase ensure consistent and reliable deployments across different stages of development?
Looking forward to seeing how Phase enhances security and efficiency for engineering teams. Great work! ๐
@nimishk@rohan_chaturvedi
This looks fantastic, @nimishk! The ease of integrating with tools like GitHub and AWS is a game-changer for teams. Excited to see how Phase can streamline secrets management! Upvoted! ๐
Hey,
Questions:
1. How does it handle secret rotation and versioning?
2. For teams transitioning from other secret management tools, do you offer any migration utilities or guides to help streamline the process?
Congrats on the launch!
Hey @kyrylosilin
Great questions! ๐
1. Secret rotation and versioning: You can set up auto-rotation for secrets on your preferred schedule. There's also a git-style history view where you can see all secret changes over time and roll back to previous versions if needed.
2. Migration: Yes, we have guides for importing secrets from certain secret managers like Hashicorp Vault and AWS Secrets Manager at this time, but we can certainly create a new guides and offer migration assistance if you're using something else.
Cool if I DM on Twitter/X?
Congrats on the launch of Phase, @nimishk! ๐ As someone whoโs seen the challenges of managing application secrets firsthand, this tool looks like a lifesaver. The seamless integration with existing workflowsโwhether it's GitHub, Docker, or AWSโalong with end-to-end encryption, makes Phase a must-have for fast-moving engineering teams.
Canโt wait to dive into the GitHub repo and give Phase a try in our next project. Upvoted and looking forward to seeing how this evolves! ๐
Phase is a powerful open source application secrets manager ideal for dynamic engineering teams. An indispensable tool for secure and efficient application deployment.
Loving the direction Phase is going, @nimishk! ๐ฅ The integration with tools like GitHub and AWS is a game changer for secure deployments. Can't wait to try it out! Upvoted! ๐
Phase