Develop Novaremix Secrets Vault

Cliente Freelancer · Remoto · Remoto · freelance · mid

Publicada el 2026-07-23

Descripción de la oferta

I am building Novaremix Vault, an open-source, self-hosted platform that keeps every secret—API keys, passwords and tokens—in one encrypted place and makes them available to applications only at runtime. The core work centres on three pillars: • Centralised secrets management – a clean REST/GraphQL API (plus CLI if you prefer) that lets me create, read, update, revoke and audit secrets under strict role-based access. • Encrypted storage – server-side encryption-at-rest with modern crypto (AES-256-GCM / ChaCha20-Poly1305 or similar) and TLS in transit, exposed through a pluggable storage backend so I can point it at a local disk today and an object store tomorrow. • Runtime secret injection – sidecar or agent pattern that can pass secrets into containers, VMs or bare-metal processes without writing anything to disk. Integrations are essential. The service must talk fluently to major cloud providers (AWS, Azure, GCP), slot into common CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, etc.) and issue short-lived credentials for relational and NoSQL databases. Webhooks or a lightweight SDK for other languages would be a bonus. I would like everything container-ready; a docker-compose file for local testing and Kubernetes manifests/Helm chart for production are expected. The full source must be MIT or Apache-2.0 licensed, with clear README, API docs and a small demo project that shows an app pulling its secrets from the vault at runtime. Acceptance criteria 1. Secrets are stored encrypted, never appear in plaintext at rest, and can be rotated or revoked instantly. 2. A working injection mechanism proves that an application container receives its secrets only on startup. 3. Cloud, CI/CD and database integrations are demonstrated with simple end-to-end examples. 4. Unit tests cover the core cryptographic and access-control logic; a basic CI workflow runs them on every push. If you have prior experience with HashiCorp Vault, Doppler, or Mozilla SOPS, that background will translate well here, but I’m open to fresh architectural ideas. Let me know how you would approach the build, the tech stack you favour, and an estimated timeline for MVP, alpha and stable releases.

Skills

Fuente original: freelancer

Análisis JobHunter