Burrow ·

Burrow 5.1.3

Machines hear about changes the moment they're saved, apps can keep their identity in memory, your Burrow answers HTTP on your own network and can open your router in one click, runs on Docker and starts at boot, and you can log out every other session in one step.

Machines#

Changes reach machines as they're saved. A machine can follow every secret it can read over one connection and hear about a change the moment it's saved. The SDKs' new live secrets use it, and ratel run --watch restarts your command straight away.

Read a whole environment at once. A machine can read every secret in an environment in one request. ratel run uses it to start your command with all of an environment's secrets. Canaries are never included.

Machines that end when your app does. An app that keeps its identity in memory ends its machine when it shuts down, so the machine moves to Expired on the Machines page the moment the app stops.

In-memory identities take a machine token. A one-time invitation's code is refused for an identity kept only in memory, and the invitation stays unused. The refusal is in the audit log.

Networking#

HTTP on your own network. Your Burrow answers plain HTTP on its usual port for anything on its own network, alongside HTTPS. A tunnel or reverse proxy on the same machine or your network, like cloudflared, can point straight at http://localhost:12010 with no settings to turn off. From outside your network, HTTP still takes you to HTTPS.

Open your router with one click. If your Burrow isn't reachable from outside your network, Remote access offers to open it for you. Your Burrow asks your router over UPnP or NAT-PMP to forward its port, keeps it open, and asks again after a restart. You can remove it at any time.

Install#

Run it with Docker. The Burrow is on Docker Hub as ratelkey/burrow, for Linux on x86-64 and ARM64. Updates work as they do everywhere else, from the Burrow's own Update button, and survive the container being recreated.

Start your Burrow at boot. Linux downloads include install-systemd.sh: run it once with sudo and your Burrow starts with the machine. macOS downloads include a launchd file that does the same.

Sessions#

Log out other sessions. The Sessions page has a button that logs out every other session in one step and keeps you logged in. With permission to end other members' sessions, it logs them out too, for when you need everyone to sign in again.

Where and when sessions started. Each session shows its location, when it was created and when it was last used, and you can log out the session you're on from its row.

The owner's sessions are the owner's. Only the Burrow's owner can log out the owner's sessions, whatever role another member has.

CLI sign-ins by name. A sign-in with ratel login shows as Ratel CLI with the computer's name, so you can tell it apart and log it out.

Fixes#

Remote access shows the machine's own local address on a host running a VPN.

The startup log names the address to open your Burrow at, over HTTPS and, on your own network, HTTP.

A secret's menu lists Audit History before Share.

Learn more in the docs.

Burrow

[email protected]

Building RatelKey — a self-hosted secrets manager whose decryption key never leaves your infrastructure.

Keep reading