TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Infisical – open-source HashiCorp Vault alternative

284 pointsby vmatsiiakoalmost 2 years ago

17 comments

vmatsiiakoalmost 2 years ago
HashiCorp switched Vault from MPL to BSL license yesterday. The terms of how they define &quot;competitive&quot; products are pretty vague, which means that any commercial product that uses Vault under the hood is at risk of violating the terms of the new license. Moreover, even if it&#x27;s not violating the terms of license now, it doesn&#x27;t mean that HashiCorp will not change its mind in future.<p>Ultimately, it just means that HashiCorp is not an open source company anymore. One of the biggest benefits of open source is building on top of open source software to create even better software. HashiCorp&#x27;s move makes it impossible and simply slows down innovation. In fact, in their blog post, they say that they will start referring to their previously-open-source product as &quot;community&quot;.<p>Infisical is an open source alternative to HashiCorp Vault. The main difference is that it provides more tools in one platform. Some examples of these are automatic secret scanning and leak prevention, CLI for local development, integrations with services like GitHub Actions, Circle CI, etc.<p>The core of Infisical is available under the MIT license with only very few features being enterprise-licensed – some will say it&#x27;s not ideal but at least this type of license does not impose legal risks on our users while gives us the ability to monetize the product efficiently and support the open source (MIT-based) part of the product.<p>Over the last year, lots of developers and companies of all sizes (from tiny startups to Fortune 10 companies) have partially or fully switched to Infisical. For them, we now process over 300 million secrets per month.<p>Check out our git repo here: <a href="https:&#x2F;&#x2F;github.com&#x2F;Infisical&#x2F;infisical">https:&#x2F;&#x2F;github.com&#x2F;Infisical&#x2F;infisical</a>
评论 #37092723 未加载
评论 #37095742 未加载
评论 #37095092 未加载
评论 #37092272 未加载
throwawaaarrghalmost 2 years ago
Backed by another corporation trying to monetize it. This will go well.<p><pre><code> This repo available under the MIT expat license, with the exception of the ee directory which will contain premium enterprise features requiring a Infisical license. </code></pre> I just sprained my eye sockets from rolling my eyes too hard.
评论 #37092576 未加载
评论 #37092585 未加载
评论 #37093934 未加载
评论 #37094397 未加载
评论 #37094922 未加载
iLoveOncallalmost 2 years ago
And still world-class testing: <a href="https:&#x2F;&#x2F;github.com&#x2F;Infisical&#x2F;infisical&#x2F;blob&#x2F;main&#x2F;backend&#x2F;tests&#x2F;integration-tests&#x2F;routes&#x2F;v2&#x2F;secrets.test.ts">https:&#x2F;&#x2F;github.com&#x2F;Infisical&#x2F;infisical&#x2F;blob&#x2F;main&#x2F;backend&#x2F;tes...</a><p>Don&#x27;t use this untested mess to store your secrets.
danenaniaalmost 2 years ago
EnvKey (<a href="https:&#x2F;&#x2F;www.envkey.com&#x2F;">https:&#x2F;&#x2F;www.envkey.com&#x2F;</a>) is another OSS alternative to Vault with a bit more focus on security (disclaimer: I&#x27;m the founder).<p>We have a comparison with Vault here: <a href="https:&#x2F;&#x2F;www.envkey.com&#x2F;compare&#x2F;hashicorp-vault&#x2F;">https:&#x2F;&#x2F;www.envkey.com&#x2F;compare&#x2F;hashicorp-vault&#x2F;</a><p>We&#x27;ll probably write up a comparison with Infisical soon as well but I&#x27;d say the main thing is that our end-to-end encryption has no opt-outs (as Infisical does for many of its integrations), and we use native apps and a CLI rather than offering a web UI. End-to-end encryption in a web browser offers minimal security benefit for reasons discussed in this thread: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=21838795">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=21838795</a> (the discussion is from 2019 and the original NCCGroup link from 2011 is now dead, but all the same issues still apply).<p>Also, I&#x27;m not sure if this has been addressed yet, but it has previously been noted that Infisical was completely lacking in automated tests. EnvKey has an extensive test suite ( core tests here: <a href="https:&#x2F;&#x2F;github.com&#x2F;envkey&#x2F;envkey&#x2F;tree&#x2F;main&#x2F;public&#x2F;app&#x2F;tests">https:&#x2F;&#x2F;github.com&#x2F;envkey&#x2F;envkey&#x2F;tree&#x2F;main&#x2F;public&#x2F;app&#x2F;tests</a> and tests for all our sdks are included in each: <a href="https:&#x2F;&#x2F;github.com&#x2F;envkey&#x2F;envkey&#x2F;tree&#x2F;main&#x2F;public&#x2F;sdks">https:&#x2F;&#x2F;github.com&#x2F;envkey&#x2F;envkey&#x2F;tree&#x2F;main&#x2F;public&#x2F;sdks</a>).
评论 #37098400 未加载
评论 #37092676 未加载
评论 #37097694 未加载
评论 #37103214 未加载
mirzapalmost 2 years ago
I remember trying Infiscal, and I was excited to see how good it is, the feature list in the OSS version, and its ease of use... What cooled me off is this limitation in OSS: &quot;3 Infisical Projects, 3 Environments &amp; 5 Team Members.&quot;<p>That&#x27;s not nice. It&#x27;s OK to limit SSO access to OSS and stuff like that. But limiting essential features - team members is a no-go.
评论 #37095199 未加载
评论 #37092662 未加载
lars_franckealmost 2 years ago
Last time I saw this mentioned here a few weeks ago someone mentioned that the whole code has no tests.<p>Is that (still) true? If so: No
评论 #37095413 未加载
评论 #37094105 未加载
评论 #37095832 未加载
rstat1almost 2 years ago
MIT now, but in a few years when the inevitable need to make profit number bigger crops up they&#x27;ll be doing the same thing.<p>And there will the same backlash by people pretending that the change is some sort of grave slight and make bold claims about how they&#x27;re switching away because they actually have to pay for stuff now.<p>And the cycle will repeat ad nauseam.
评论 #37098415 未加载
drdaemanalmost 2 years ago
So the introduction says it’s “end-to-end encrypted” but all it does is a link to Wikipedia (which is useless). Is there any documentation on the security model?<p>Vault has some at-rest encryption but IIRC explicitly says then don’t have any mitigations against a compromised unsealed node. My understanding is that if someone ever gets a root access to a machine running Vault, the game is over. Which makes me wonder ifI can deploy Infiscial to some completely untrusted machine (without any orchestration or networking concerns) and still have some guarantees that all my secrets are safe in some way (cannot be decrypted, cannot be replaced, maybe even cannot be rolled back, etc)?
评论 #37097469 未加载
sergiotapiaalmost 2 years ago
There has to be a middle ground where yes you can use this to your hearts content for free, but don&#x27;t package and sell this to undercut our own hosted offering.<p>It&#x27;s pretty shitty what happened with mongodb and aws. Morally it always felt wrong.
chrisfrantzalmost 2 years ago
Congrats to the Infisical team, it&#x27;s been cool getting to watch them grow from the start.<p>What are some of the biggest challenges you&#x27;ve run into so far?
评论 #37092573 未加载
评论 #37092569 未加载
pluto_modadicalmost 2 years ago
I wish secret manager services were obsoleted by OIDC and HSMs. If everything negotiated via keypass &amp; beyondprod style workload identification and... we never save passwords for DBs or web hooks ever again.<p>...it&#x27;s annoying that a kubernetes-like complex system exists and it doesn&#x27;t have to. And now they have a SaaS version for small numbers of secrets....
smartbitalmost 2 years ago
Does Infisical support an HSM?
评论 #37092666 未加载
评论 #37092784 未加载
ksajadialmost 2 years ago
Infisical 3rd party integrations are one of the best things about it. They just work without having to deal with plugins or crazy configurations. Kudos to the team.
revskillalmost 2 years ago
I tried infsical before, it&#x27;s bad.<p>It lacks of the most important feature: Auto save your form.
评论 #37098000 未加载
ckwalshalmost 2 years ago
Any plans for OIDC support?
评论 #37093774 未加载
dvrpalmost 2 years ago
Do you have other near-term next plans besides secret management?
评论 #37092248 未加载
Jishinalmost 2 years ago
Another option, for companies that want to go full security over automations and kubernetes, is CyberArk Conjur. Its OpenSource is quite limited in features, but the Enterprise version is very complete.