Password store template for teams
This repository contains a base template for a password store repository to be used by teams.
It contains:
A README.md to adapt to your team
A script to setup a unique alias based on the directory name.
A Makefile with some common toolsViele DevOps-Teams gehen mit ihnen anvertrauten Credentials wie Passwörtern oder Zertifikaten sorglos um. Verglichen mit Slack Tokens, die versehentlich auf GitHub exponiert wurden, ist ein Schaden bei Infrastructure as Code schnell deutlich größer. Immerhin ist das Äquivalent eines Rechenzentrums bedroht.
Alte Ansätze wie versiegelte Umschläge im Safe oder fein abgestimmte Active-Directory- oder LDAP-Integrationen funktionieren in der verteilten und dynamischen DevOps-Welt oft nicht mehr. Leider gibt es aber auch noch kein wirklich etabliertes "leichtgewichtiges" Set von Werkzeugen für das Credential-Management. Was also tun, wenn das eigene DevOps-Team schnell wächst, die Zahl der verwendeten Tools schon weit zweistellig ist und die Komplexität dennoch beherrschbar bleiben soll? Gesucht ist eine Möglichkeit für Credential-Management, die zu den verwendeten Tools passt und gleichzeitig die dadurch zusätzlich eingeführte Komplexität niedrig hält.
Password management should be simple and follow Unix philosophy. With pass, each password lives inside of a gpg encrypted file whose filename is the title of the website or resource that requires the password. These encrypted files may be organized into meaningful folder hierarchies, copied from computer to computer, and, in general, manipulated using standard command line file management utilities.
pass makes managing these individual password files extremely easy. All passwords live in ~/.password-store, and pass provides some nice commands for adding, editing, generating, and retrieving passwords. It is a very short and simple shell script. It's capable of temporarily putting passwords on your clipboard and tracking password changes using git.
You can edit the password store using ordinary unix shell commands alongside the pass command. There are no funky file formats or new paradigms to learn. There is bash completion so that you can simply hit tab to fill in names and commands, as well as completion for zsh and fish available in the completion folder. The very active community has produced many impressive clients and GUIs for other platforms as well as extensions for pass itself.
The pass command is extensively documented in its man page.