Burrow ·

Burrow 2.2.0

Canary secrets that disable any machine that reads them, and breadcrumb navigation across your projects and environments.

Canary secrets#

Plant a canary among your real secrets. In any environment, open New secret and choose Canary. It is a decoy with a value generated for you, and it sits in the list looking like any other secret. Nothing of yours should ever read it, so a read means something is going through your secrets that should not be.

A machine that reads it is disabled at once. The moment one of your machines fetches a canary, that machine is disabled, so whatever is using its credentials loses access on its next request. It keeps its identity and its grants, so once you have looked into what happened you can turn it back on. The reader is still handed a value, so whoever is probing has no sign they tripped anything.

You see exactly what tripped it. The read and the disable both land in your audit log, naming the machine, so you can tell which one it was and shut down whatever is using its credentials.

Armed by default, yours to control. A canary is armed the moment you create it. Disarm it from its row to record reads without disabling anything, and arm it again whenever you want. Revealing a canary inside the dashboard never trips it; only a machine read does.

Getting around#

Move through your projects by breadcrumb. A project, its environments, and its secrets now sit under a breadcrumb at the top of the page. Each step is clickable, so you can jump back up to the environment or the project in one click.

Tidier secret menus. The actions menu on a secret groups Rename with the other edit options, above Delete, so the destructive action stays on its own at the bottom.

Learn more in the docs.

Burrow

[email protected]

Building RatelKey — a self-hosted secrets manager whose decryption key never leaves your infrastructure.

Keep reading