Full-stack Engineer / in progress
Envy
Encrypted team secrets with workspace RBAC and a Go CLI for secure developer workflows.
- Go
- Gin
- PostgreSQL
- React
- Vite
- TailwindCSS
- Docker
- CLI

THE PROBLEM
What needed to work better
Teams need to share secrets across projects and environments without losing track of who can access them or how they were used.
THE DECISION
The choice that shaped it
Keep the security boundary explicit: encrypt secret values with AES-256-GCM, use AWS KMS for envelope encryption, and make workspace roles part of the data model.
HOW IT FITS TOGETHER
A path through the system
- 01Web app
- 02Workspace roles
- 03Encrypted secrets
- 04Go CLI
WHAT EXISTS NOW
The result
A full-stack secrets manager with organization and workspace access, audit logging, and a Go CLI for working with secrets from development workflows.
IN THE BUILD
Details that matter
- AES-256-GCM encryption with AWS KMS envelope encryption (fallback in dev)
- Google OAuth authentication flow
- Organizations, projects, environments, and secret CRUD with RBAC
- CLI login + pull to write secrets to local .env files
- Docker Compose deployment with reverse proxy