Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Keeper

embedded secret store for Go (help me break it)

Details

External ID
47715339
Source
HN
Company
—
Product
Keeper
Website domain
github.com
Launched
April 10, 2026
Cohort
—
Upvotes
64
Upvotes percentile
0.8618251928020566
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Keeper is an embeddable secret store (Argon2id, XChaCha20-Poly1305 by default). Four security levels, audit chains, crash-safe rotation. Vault is overkill for most use cases. This is for when you ge paranoid about env and need encrypted local storage that doesn't suck. No security through obscurity, hence, It's still early, so now's the best time to find weird edge cases, race conditions, memory leaks, crypto misuse, anything that breaks. The README has a full security model breakdown if you want to get adversarial.

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
secret management for go applications
Manually corrected
False

Could you build this?

No Implementing cryptographic primitives, secure memory management, and crash-safe audit chains requires rigorous cryptographic domain expertise where AI hallucinations can cause catastrophic vulnerabilities.

What it would actually take: Building this requires cryptographic systems engineering in Go using libraries like golang.org/x/crypto. The architecture involves custom crash-safe WAL/journaling, strict memory zeroing to avoid secrets leaking into swap/dumps, and tamper-evident cryptographic hash chains. It requires deep expertise in applied cryptography, security auditing, and low-level Go runtime internals.

Discussion

20 comments analyzed.

Competitors mentioned: OIDC in CI/CD for eliminating stored secrets, fnox for unified secrets access across dev/CI/prod, Keeper Security for credential management, age + filesystem secrets manager, secret (Go CLI-focused secrets manager)

Concerns raised: WAL approach not atomic, can corrupt on crash, Key management at scale complexity, Single bbolt database limitation, Audit system ineffective if on compromised machine, Product name confusion with Keeper Security

Feature requests: Append-only log instead of WAL for crash safety, Post-quantum KEMs like ML-KEM support, External WAL for true crash-safe rotation, Multiple database backend options beyond bbolt

Competitors

Other products that read as similar to this one — 123 launches clear the similarity bar, closest 8 shown.

Attention rank: #25 of 124 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 162 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.