Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

SecretEnv

Run any process with secrets from all your backends

Details

External ID
48024563
Source
HN
Company
—
Product
SecretEnv
Website domain
github.com
Launched
May 5, 2026
Cohort
—
Upvotes
5
Upvotes percentile
0.1147011308562197
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Hi Guys,I built SecretEnv to help solve one common thing that I have seen at every org, that I have worked at.We always had more than one password/credential manager. Service tokens maybe in Vault, AWS SSM etc and some team specific service account or temp account credentials being store in another password store such as 1Password or Keeper, there was never one single credential store.This is where SecretEnv comes in play, it runs any command with secrets injected as env vars, sourced from whatever combination of backend your team already uses.I am sure there are other tools as well that do a similar thing, which is run a command and inject secret. However SecretEnv does one thing differently.The key idea is separating two items which are most of the time combined. Think of SecretEnv's resolution structure like an Address Book.- Your repo gets a secretenv.toml file which has labels in there as values against ENV Vars. These can be literally anything. DB_URL, STRIPE_KEY whatever.- You have a registry that lives in your backend that you/your company uses. This registry holds the actual paths so the credentials.- You have a config file on your machine called config.toml that secretenv uses to grab the aliases from secretenv.toml and resolve against registry that lives in your backend.So imagine if you are a Platform Engineer and need to migrate password stores to different backend.You can now migrate secrets from AWS to Vault or change the naming conventions in one central place (registry) without devs having to touch their code or update config file.What this means is if the credential is used by 10, 15 or even 20 repos. All you need to do is update the alias in the registry and all repos pick up the changes.No need to open PR's, involve dev teams.The whole idea was abstracting and decoupling the dependency.The tool currently supports 14 backends already which covers most of the ground.Would love your feedback and if there is any backends or workflow that this does not cover.https://github.com/TechAlchemistX/secretenv

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
run processes with secrets from multiple backends
Manually corrected
False

Could you build this?

Yes It is a CLI wrapper utility that fetches key-value secrets from external services (Vault, AWS SSM) via their SDKs and spawns a child process with those environment variables injected.

Discussion

8 comments analyzed.

Competitors mentioned: varlock, fnox, mise

Concerns raised: Encryption/decryption dependency creates coordination burden for password rollouts across multiple repos, Scaling password store migrations requires updating multiple repositories instead of single source, User offboarding complexity when secrets are stored in repos vs centralized IAM

Feature requests: Compose with varlock for validation on top of backend fetching, KMS integration support documentation

Competitors

Other products that read as similar to this one — 142 launches clear the similarity bar, closest 8 shown.

Attention rank: #129 of 143 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 185 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.