leetcrypt 35f19c007a rotate: 6 service-API drivers (mongo, npm, gcp, twilio, flyio, k8s)
Each driver is real-service code only (no test awareness; tests inject just an
HTTPClient/Bin), following the established patterns:

- mongo: in-place changeUserPassword over the old connection; no secret on argv
  (host/db on the URI, both passwords on stdin, output scrubbed).
- npm:   create token -> /-/whoami -> delete-by-key; blob records the key.
- gcp:   service-account KEY rotation; mints an RS256 JWT signed with the SA's
  own private key (crypto/rsa, stdlib) to self-auth the IAM create/verify/delete.
- twilio: API Key create -> get -> delete, Basic auth (KeySid/secret).
- flyio: GraphQL — a managing token mints/deletes the rotated deploy token.
- k8s:   create a service-account-token Secret, await the populated token,
  verify against the SA, delete the old Secret (invalidates the old token).

All 6 register their honest proof level (MOCK-ONLY) in proofs.go +
ROTATION-PROOFS.md; mongo/npm/k8s are LIVE-VM candidates pending real-target VM
POCs. Emulators enforce credential validity (gcp verifies the JWT signature),
tests assert Verify(old) fails after revoke + a secret-leak canary.

Full suite: 103 green, -race clean on rotate/sink/vault.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-06-18 15:57:59 -07:00

Incredigo — guards your credentials in locked memory, leaves no trace on disk

Incredigo

Guards your credentials in locked memory. Leaves no trace on disk.

Local-first, encrypted, RAM-only credential custody — shipped as the incredigo CLI.

+------------------------------------------------------------+
|    /\      INCREDIGO                                       |
|   /<>\     in-CRED-i-GO : credentials, in Go               |
|   \<>/     Guards your credentials in locked memory.       |
|    \/      Leaves no trace on disk.                        |
+------------------------------------------------------------+

Incredigo finds credentials scattered across the usual places (~/.aws/credentials, .env files, ~/.netrc, SSH keys, ~/.docker/config.json, kubeconfig, …), migrates them into a gopass (GPG-backed) store without ever writing plaintext to disk, and tells you which ones are stale.

  • 🔒 No plaintext at rest. Disk only ever holds GPG blobs (gopass) or openssl-sealed backups.
  • 🧠 RAM-only secrets. Decrypted material lives in mlock'd, non-dumpable, zeroized memory (memguard).
  • 📴 Offline. v1 makes zero network calls.
  • 👀 Read-only discovery. Scanners never touch your source files.
  • 🧩 Hackable. A new source is one file; the backup format is an interface.

See DESIGN.md for the architecture and threat model.

Why the name

Incredigo is one word hiding three:

  in · CRED · i · GO
        └┬─┘       └┬┘
   CREDentials   in GO

It manages your CREDentials, it's written in GO, and read aloud the whole thing lands on incredible — which is the bar a credential tool that promises "no plaintext on disk, ever" has to clear.

The mark

The logo is Strata — nested diamonds tightening around a single bright core. It's the whole tool in one glyph: each ring is a layer of custody (read-only discovery → locked-memory vault → GPG/OpenSSL at rest), and the core is your secret, held in RAM and never written out. The design is deliberately abstract and geometric — no mascot, no metaphor to decode.

What it does How
Finds, doesn't guess Real parsers per source — no blind grep, no false positives.
Composes, doesn't invent Battle-tested GPG (via gopass) and OpenSSL; no home-rolled crypto to break.
Holds, doesn't leak Read-only discovery, RAM-only custody, redacted audit log — plaintext never leaves the locked arena.
Works, then vanishes No server, daemon, network, or temp files; it does its job and leaves nothing on disk.

The brand is Incredigo, and so is the command: the CLI was renamed from its old working title credrot so the tool and the project finally share a name.

Status

v1 scope: discover + migrate + expiry tracking. Provider-driven rotation (issue-new / verify / revoke-old) is planned for v2 behind a stable interface.

export/import are stubbed in this scaffold (see cmd/incredigo/main.go).

Rename in progress: the Go package and binary are being renamed credrotincredigo. Until that lands, substitute ./cmd/credrot / credrot in the commands below.

Build

Requires Go 1.22+.

go mod tidy
go build ./cmd/incredigo

Usage

incredigo scan --dry-run                 # see what's out there (no secrets printed)
incredigo migrate --prefix imported/ --dedupe
incredigo status                         # age vs policy
incredigo export --out ~/incredigo-backup.enc   # (v1 stub)

Layout

Path Purpose
cmd/incredigo cobra CLI
internal/vault RAM-only secret arena (memguard)
internal/discover scanner registry + one file per source
internal/sink gopass writer + Sealer interface + openssl impl
internal/policy expiry rules
internal/audit redacted append-only log

Contributing

Adding a source is intentionally easy — see docs/ADDING_A_SCANNER.md.

S
Description
Local-first, encrypted, RAM-only credential custody + backup-gated rotation (Go)
Readme 3 MiB
Languages
Go 88.5%
Shell 9.2%
Python 2%
Makefile 0.3%