Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
19 results
label:secrets

Gcp Sm

@swamp/gcp-sm · v2026.09.10.0

Read, write, and delete secrets stored in Google Cloud Secret Manager, with

upd Sep 1017 pullsA100/100

Azure Kv

@swamp/azure-kv · v2026.09.10.0

Read, write, and delete secrets stored in Azure Key Vault. Supports secret

upd Sep 10291 pullsunscored

Aws Sm

@swamp/aws-sm · v2026.09.10.0

Read, write, and delete secrets stored in AWS Secrets Manager, with support

upd Sep 10697 pullsA100/100

1password

@swamp/1password · v2026.09.10.0

Read, write, delete, and annotate secrets stored in 1Password using the `op` CLI.

upd Sep 1036k pullsA100/100

Credential Expiry

@sntxrr/credential-expiry · v2026.09.09.1

Probe the credentials a fleet actually holds and report how long each has left, distinguishing expiry from an outage in progress

upd Sep 918 pullsA100/100

Griptape/secrets

@webframp/griptape/secrets · v2026.08.29.1

Griptape Cloud Secrets — organization secret management

upd Aug 300 pullsA100/100

Pass

@webframp/pass · v2026.08.28.1

GPG-encrypted password store using the pass CLI (passwordstore.org). Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and backend only — never secret values or error messages.

upd Aug 2828 pullsA100/100

Macos Keychain

@webframp/macos-keychain · v2026.08.28.1

macOS Keychain vault using the security CLI. Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and keychain service only — never secret values, argv, or error messages.

upd Aug 2856 pullsA100/100

Hashicorp Vault

@webframp/hashicorp-vault · v2026.08.28.1

HashiCorp Vault secrets management via REST API (KV v1 and v2). Emits OpenTelemetry spans for get, put, and list, with one child span per request in the recursive list walk, so vault reads are visible in traces including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and KV version only — never secret values, tokens, or error messages.

upd Aug 2880 pullsA100/100

Gopass

@webframp/gopass · v2026.08.28.1

gopass password manager (gopass.pw) - pass compatible with extra features. Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and backend only — never secret values or error messages.

upd Aug 289 pullsA100/100

Github/secrets

@hivemq/github/secrets · v2026.08.27.1787839773

GitHub Actions secret management via the local gh CLI. Supports repo-level, environment-scoped, and organization-scoped secrets with fan-out, code-search discovery, and a dry-run mode on the org-level setter. No PAT, GitHub App, or vault-held token required — auth comes from the operator's existing gh session.

upd Aug 27109 pullsD50/100

1password Connect

@sntxrr/1password-connect · v2026.08.05.1

A swamp vault backend for 1Password Connect — read and write secrets over Connect's HTTP API with a bearer token, so vault.get() works headless in cron, containers, and swamp serve without the op CLI.

upd Aug 561 pullsA100/100

Scaleway Secret Manager

@sntxrr/scaleway-secret-manager · v2026.07.19.1

Manage a Scaleway Secret Manager secret — sync/create/update/delete metadata, list secrets in a region, add new secret versions, and access secret values (returned only via a sensitive, vaulted output), via the Secret Manager API with X-Auth-Token auth.

upd Jul 190 pullsA100/100

Openbao Configurator

@evrardjp/openbao-configurator · v2026.07.17.1

OpenBao configuration rendering and API lifecycle control: render HCL, status, initialize, unseal, and seal. File deployment and service management are handled by cfgmgmt extensions.

upd Jul 172.8k pullsA100/100

Vaultwarden

@evrardjp/vaultwarden · v2026.07.03.2

Vaultwarden helper model for environment template discovery/rendering and HTTP health verification. Deployment and service management are handled by cfgmgmt extensions.

upd Jul 34 pullsA100/100

Snowflake

@mfbaig35r/snowflake · v2026.06.01.1

Snowflake warehouses, databases, schemas, stages, tasks, pipes, secrets, and grants as Swamp models. Compose Snowflake pipelines with non-Snowflake resources in Swamp workflows. Backed by the Snowflake SQL Statement Execution API (v2).

upd Jun 10 pullsA100/100

Databricks

@mfbaig35r/databricks · v2026.05.30.18

Databricks Jobs, DLT pipelines, SQL warehouses, workspace notebooks/files, secrets, Unity Catalog, permissions, DBSQL queries, and Git Repos as Swamp models. Compose Databricks pipelines with non-Databricks resources in Swamp workflows.

upd May 312 pullsA100/100

Passbolt

@phy2vir/passbolt · v2026.05.25.2

Passbolt CLI vault provider for swamp secrets

upd May 258 pullsA100/100

Sops Age

@zocc/sops-age · v2026.05.22.1

SOPS + age vault for swamp: encrypt secrets at rest with AES-256-GCM via Mozilla SOPS and age. Zero network dependency — fully local, file-based. Works with existing SOPS workflows and zo.space secrets dashboards.

upd May 2223 pullsA100/100