bank-vaults/bank-vaults
A Vault swiss-army knife: A CLI tool to init, unseal and configure Vault (auth methods, secret engines). observed · 2026-08-28
Health v2 · maintenance only
86/100
- Activity 99
- Release rhythm 61
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 120.5
- age_days: 3101
- days_rel: 100
- days_push: 9
- n_releases_24m: 7
Adoption not part of the score
2267 stars · 488 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Bank-Vaults is a CNCF Sandbox umbrella project of tools for cloud-native secret management with Hashicorp Vault. This repository provides the Go CLI that automatically initializes, unseals (via cloud KMS or HSM), and configures Vault on Kubernetes, complemented by Helm charts, a Vault operator, a secret-injection mutating webhook, and a Go SDK.
Use cases
- automatically unseal hashicorp vault on kubernetes
- initialize and configure vault auth methods and secret engines
- inject vault secrets into kubernetes pods as environment variables
- unseal vault using aws kms, azure key vault, or google cloud kms
- deploy a production-ready ha vault instance with helm
- operate vault on kubernetes without manual unseal steps
- renew vault tokens automatically from go applications
When to choose
- You run Hashicorp Vault on Kubernetes and want automated initialization, unsealing, and configuration
- You need to inject Vault secrets directly into pods, config maps, or custom resources
- You want multiple unseal options across cloud KMS providers, HSM devices, or Kubernetes secrets
- You prefer Helm-chart-based, production-ready Vault deployments with HA support
When to avoid
- You don't use Kubernetes or Hashicorp Vault, since the tooling is specific to that stack
- You need a general-purpose secrets manager rather than Vault orchestration tooling
- You want a fully managed secret store without self-operating Vault instances
- You only need a simple secrets client and don't require operator, webhook, or CLI automation
Facets
cli-tool · maturity active
secrets-management security cli configuration-management deployment security cloud-computing self-hosted go cli cloud self-hosted hashicorp-vault vault-unsealing secret-injection mutating-webhook kubernetes-operator helm-chart cncf-sandbox cloud-kms hsm istio secret-engines auth-methods devops containers kubernetes docker
6 sources
- readme: https://github.com/bank-vaults/bank-vaults · fetched 2026-08-28 · 1e55eaf03921
- homepage: https://bank-vaults.dev · fetched 2026-08-29 · 62ee0c494536
- site_page: https://bank-vaults.dev/docs/community · fetched 2026-08-29 · 89f0fd00b898
- site_page: https://bank-vaults.dev/docs · fetched 2026-08-29 · 06b4bd89f317
- site_page: https://bank-vaults.dev/docs/blog · fetched 2026-08-29 · 8d763ba4342d
- site_page: https://bank-vaults.dev/docs/installing · fetched 2026-08-29 · 2e8293f9b17b
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| bank-vaults/bank-vaults | main | 86 |
For agents
markdown · JSON · MCP: product_card(name="bank-vaults/bank-vaults")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem