← Back to archive

Repo of the Day

dopbase/dopbase: DevOps secrets base: lightweight, self-hosted secrets manager in a single file

Published: Sep 20, 2026

Open repository ↗

DevOps secrets base: lightweight, self-hosted secrets manager in a single file - dopbase/dopbase

Summary

Dopbase is an open-source, self-hosted secrets manager distributed as a single Rust binary that bundles the server, Admin UI, REST API, and CLI together. Secrets are organized by project and environment, and runtime state lives under ~/.dopbase by default, so a working setup is one install and one command. It targets teams that want a single-binary, self-hosted replacement for scattered .env files.

What it is useful for

Dopbase is aimed at engineers who need to store API keys, database URLs, and other application secrets across development, staging, and production environments without operating a multi-service platform. Its data model is intentionally small: a Project contains Environments, and each Environment holds Secrets. This shape fits solo developers coordinating between a laptop and a CI runner, small teams sharing a staging cluster, and any project where .env files have outgrown version control but a full vault product is too heavy.

Beyond storage, the server includes access control with four roles, read-only AI accounts, an audit history, encrypted backups, and a crash-safe factory reset. The CLI imports from dotenv, JSON, YAML, or TOML and exports to dotenv, JSON, YAML, TOML, or a Docker env file, so it slots into existing pipelines. One documented limitation: v0.1.0 starts with a fresh data directory, and databases and backups from earlier releases are not supported.

How engineers can use it

On macOS or Linux (AMD64 or ARM64), the documented install runs:

curl -fsSL https://dopbase.com/install.sh | sh
dopbase server start

A fresh instance prints a web setup link. To skip the browser, set [email protected] on first start; a one-time root password is generated. A typical workflow is:

dopbase login
dopbase init myapp/dev --from .env
dopbase secret set myapp/dev API_KEY --stdin
dopbase run myapp/dev -- node server.js

dopbase run injects the chosen environment's secrets into a child process without writing a shared .env to disk. For CI, create a token with dopbase token and export it as DOPBASE_TOKEN. The default server port is 8840 and the data directory is ~/.dopbase; both can be changed with DOPBASE_PORT and DOPBASE_DATA_DIR. Contributors need Bun and a Rust 2024-edition toolchain, then bun install and bun run dev.