Burrow ·

Burrow 5.4.1

Dynamic secrets that give every machine its own database login, GitLab CI/CD and Bitbucket Pipelines machines, rate limits you can tune, sign-ins in the audit log, and pages that follow changes made elsewhere.

Dynamic secrets#

A database login for every machine. A new kind of secret, Dynamic, gives each machine that reads it a database login of its own, made the moment it reads and removed when its time is up. Your Burrow signs in to the database with an admin login you give it, creates each machine's login with only the rights you grant, and hands the machine its host, port, database, username and password as fields. Machines read it with the CLI and SDKs they already have.

Six databases. PostgreSQL, MySQL, MariaDB, Microsoft SQL Server, MongoDB and Redis 6 and later. A connection pooler in front of PostgreSQL, such as Supabase's or PgBouncer, works too.

Grants without writing SQL. The grant builder writes each login's rights from a list: read-only, read and write, or full access, or privileges one by one, on the schema, database or keys you choose. Test the grants tries them on a throwaway login first, and Test connection checks the admin login can create logins.

A lease policy for each secret. Choose how long a login lasts, whether a machine that keeps reading keeps its login, a hard maximum before its password changes, a new password on every read, and whether disabling a machine removes its login at once. On PostgreSQL, the database itself can refuse a login at its end time.

See and revoke logins. Logins in the secret's row menu lists every login out, with its machine, state, and when it was issued and ends, and revokes any of them at once. Configure pauses issuing and changes the policy, grants and connection, and Version History keeps every change.

Every step in your audit log. Each login issued, renewed and revoked is recorded, and reaches your webhooks.

The dynamic secret engine comes from our parent company SikkerKey.

Machines#

GitLab CI/CD machines. A GitLab CI/CD job on gitlab.com can sign in to your Burrow with no key stored in GitLab. Add the machine for a project and its CI file, optionally pinned to one environment.

Bitbucket Pipelines machines. A Bitbucket Pipelines step can sign in with no key stored in Bitbucket. Add the machine for a workspace and repository, optionally pinned to one deployment environment, and list your Burrow among the step's OIDC audiences.

Expired machines leave your projects. When a machine expires, it's removed from every project's Machine access within 30 seconds, and expired machines can't be given access.

Tidy names. Machine, machine token and webhook names use lowercase letters, digits and hyphens, like project names. The name boxes tidy what you type as you type it.

Machine tokens filter. The Machine tokens page filters to active, all, expired or revoked tokens.

Secrets and projects#

Filter secrets by what's attached. A third filter shows linked, rotating, failing-rotation or shared secrets.

Version history in pages. Six versions at a time with Previous and Next, and a page number you can click to jump to any page, here and in the audit log.

Project descriptions. Give a project a short description when you create or rename it. It shows under the project's name.

Create a canary disarmed. New canary has an Armed switch, on by default.

Audit log#

Sign-ins. Each member signing in to your Burrow is recorded, with the address they came from, and reaches webhooks subscribed to auth.signin.

Country flags. With IP data on, addresses show their country's flag, and the location line names the country in full.

Search the actor filter. The actor filter has a search box, and the export's actor picker matches it.

Security#

Rate limits you can tune. Settings → Rate limits sets the limits per address, for the whole Burrow and for share links, each saved on its own and applied at once. It shows what each limit allowed and refused, lockouts in force with Lift, and recently refused addresses with an Exempt button.

Dashboard#

Pages follow changes made elsewhere. Secrets, projects, machines, webhooks, the Overview note and the audit log update on their own when something changes in another tab, by another member, by a machine or by your Burrow itself. A tripped canary shows a notice on any page.

Dashboard updated notice. After your Burrow updates, an open dashboard offers to refresh to the new version.

Clearer addresses. Settings → Remote access lists your Burrow's local addresses with their scheme, and the relay address with https://.

Fixes#

Faster restarts after an update. A restart after an update could take minutes. It now takes seconds, from the update after this one.

Live updates keep up. Pages stopped updating after a laptop slept or the network changed. They now reconnect on their own and pick up where they left off.

Drag to reorder. Dragging a project or secret often moved it only one place. A row now follows the pointer, shows where it will land, and moves on release, in every browser and with touch.

City and country in IP data. With IP data on, addresses showed their network but never their location. They now show the city and country too.

Addresses behind a tunnel or proxy. Behind a tunnel or reverse proxy, addresses offered and copied in the dashboard could end in :80. They now match the address you browse to.

Verifying an IP address. Encrypted + verified for an IP address now always checks your Burrow's own key, so machines reaching a Burrow with a Let's Encrypt certificate by its IP can connect.

Learn more in the docs.

Burrow

[email protected]

Building RatelKey — a self-hosted secrets manager whose decryption key never leaves your infrastructure.

Keep reading