Skip to the content.

Secrets Broker Agent

This scaffold introduces a new gnat/agents/secrets/ family designed for:

Design goals

  1. Use secret references everywhere possible.
  2. Keep raw values at execution boundaries only.
  3. Enforce policy before touching a vault.
  4. Treat hygiene scanning as part of the same system, not an afterthought.
  5. Preserve room for CyberArk’s account checkout and rotation model.

Phase A included here

Phase B candidates

Phase C candidates


Licensed under the Apache License, Version 2.0