Antares is a tool who can synchronize an HashiCorp Vault server, and a KeePass file.
In a nutshell, you can import your KeePass secrets to a Hashicorp Vault instance, and export Vault secrets to an offline Keepass.
The most of the configuration is made through CLI. When exporting, you must also provide a JSON file who will include the Vault paths you want to export.
Configuration arguments:
- Mandatory:
-importor-export: Define the action you want to do. Import will import secrets from KeePass to Vault, export will export Vault secret to a new KeePass file.-password=<your_password>: The password of your KeePass database. If you are exporting secrets, the KeePass file will be created with this password.- This argument can also be provided through
ANTARES_KEEPASS_PASSWORDenvironment variable.
- This argument can also be provided through
-vaultToken=<you_vault_token>: The Vault token corresponding to your account. You can get one by simply log-in into the Vault UI.- This argument can also be provided through
ANTARES_VAULT_TOKENenvironment variable.
- This argument can also be provided through
-vaultServer=<your_vault_server>: The address of your Vault instance.
- Optional :
-keepassFile=<path_to_your_keepass.kdbx>: The input/output KeePass location.- By default, this value is set to
./vault-keepass.kdbx
- By default, this value is set to
-configFile=<path_to_your_configuration_file.kdbx>: The configuration file, as described below.- By default, this value is set to
./configuration.json
- By default, this value is set to
The configuration file allows you to specify which paths of your Vault you want to export. If a secret ends with a /, the sub-secrets will also be retrieved.
For example:
[
{
"engine": "gitlab",
"paths": [
"/project1/",
"/project2/secret"
]
},
{
"engine": "home",
"paths": [
"/"
]
}
]With this configuration file, the tool will save in your KeePass:
- All secrets in
project1folder ingitlabengine; - The specific secret named
project2/secretingitlabengine; - All secrets that will be find in
homeengine.
go mod downloadgo build -o antares ./cmdgo run ./antares <your_arguments>
This project is released under MIT license.