Portunus¶
A standalone, boundary-only secret broker — reference a secret by name; the value is injected only at the execution boundary, never inside an LLM or agent context.
Documentation¶
- Quickstart — Install, store your first secret, and run your first
resolve --execin a few minutes. - Core Concepts — Reference, ARCA, OSTIARIUS, Petitio, injection modes, the audit chain, and the fail-closed default.
- Architecture — Component diagrams, ARCA backend-selection precedence, the full request/resolve sequence, and opt-in access control.
- Rotation Guide — What rotates automatically, what doesn't, and what you need to do by hand.
- Provider Rotation Matrix — Per-provider rotation capability reference.
Links¶
- Source: github.com/mdostal/portunus
- Install:
curl -fsSL https://mdostal.github.io/portunus/install.sh | bash