Skip to content

3rd party secrets-engine plugin backends #534

@joe0BAB

Description

@joe0BAB

The secrets engine resolves se://<id> references through plugins. Below are candidate backends we're considering, grouped by where they fit in a user's workflow.

Locally-usable backends

Routinely used from a developer's machine, personal/team password managers, or self-hostable secret servers a developer authenticates to with a token.

  • 1Password (ships June 8, 2026 / Docker Desktop 4.77.0)
  • Bitwarden (with Vaultwarden as a self-hosted, API-compatible option)
  • LastPass
  • HashiCorp Vault
  • OpenBao

Cloud-deployment backends

Primarily used by workloads running in a cloud, reading secrets provisioned in that same cloud (IAM role, managed identity, workload identity).

  • AWS Secrets Manager
  • AWS SSM Parameter Store
  • Azure Key Vault
  • Google Cloud Secret Manager

Vote for the plugin you want most scroll down and react with 👍 on the comment for that backend. The more reactions a backend gets, the sooner it moves up our list.

Don't see your secret store? Drop a new comment with the backend you'd like supported and a short note on how you use it (personal workstation, CI, production workloads, …).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No fields configured for Epic.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions