
cottage v0.6.7
टीमों के लिए एक आधुनिक git-आधारित age-एन्क्रिप्टेड सीक्रेट्स मैनेजर।
cottage टीमों के लिए एक GitOps टूल है जो git रिपॉज़िटरी में age-encrypted secrets को प्रबंधित करता है।
यह secrets को encrypt/decrypt करने, recipients को प्रबंधित करने, और secrets को रेपो से बाहर रखने के लिए एक सरल workflow प्रदान करता है, साथ ही VCS के माध्यम से आसान शेयरिंग की सुविधा देता है। cottage एन्क्रिप्टेड secrets के redacted previews भी जनरेट करता है ताकि बेहतर visibility मिल सके, और persistent तथा temporary decryption workflows दोनों का समर्थन करता है, जबकि यह सुनिश्चित करता है कि secrets कभी भी plaintext में commit न हों।

- Features
- Installation
- Editor Integrations
- AI Agent Integrations
- Quick Start
- GitOps
- Git Hooks
- Access Control
- Any Provider as Upstream
- Sync with any device
- Learn More
- Troubleshooting
- Comparison
Features
- Exposure-safe: Rust के type system का उपयोग करके यह सुनिश्चित करता है कि bugs कभी भी गलती से secrets को expose न कर दें।
- Team-friendly: रेपो में public keys (recipients) शेयर करें, private keys (identities) को local रखें।
- Access Control: सरल allow/deny नियमों से नियंत्रित करें कि कौन से secrets किन recipients के लिए encrypt किए जाएँ।
- Manages .gitignore: unencrypted secrets को रेपो से बाहर रखने के लिए स्वचालित रूप से
.gitignoreको अपडेट करता है। - Previews: बेहतर visibility के लिए एन्क्रिप्टेड secrets के timestamped redacted previews जनरेट करता है।
- Rich diffs: git diff को साफ़ और reviewable रखता है, जबकि
ctg difflocally modified secrets का tracked encrypted counterparts के साथ diff दिखाता है। - Checksum verification: यह सत्यापित करके tampering रोकता है कि encrypted secrets और recipient lists metadata से मेल खाते हैं।
- Git hooks: commit से पहले secrets को स्वचालित रूप से check/encrypt करने और checkout के बाद decrypt करने के लिए आसानी से git hooks सेट करें।
- Persistent secrets workflow:
ctg decrypt/syncdecrypted secrets को disk पर रखता है। - Smart cleanup lifecycle:
ctg run(shortcutctgx) औरctg editऑपरेशन से पहले secrets को decrypt करते हैं, और यदि वे पहले से disk पर मौजूद थे तो उन्हें रखते हैं, अन्यथा बाद में स्वचालित रूप से साफ़ कर देते हैं। - Clean on completion:
ctg encrypt --clean,ctg run --clean, औरctg edit --cleanयह सुनिश्चित करते हैं कि decrypted files disk से साफ़ हो जाएँ, भले ही वे पहले मौजूद थे। - Environment injection workflow:
ctg envdecrypted secrets को environment variables के रूप में inject करके command चलाता है, बिना उन्हें disk पर लिखे। - Secure secret piping:
ctg cat PATHmemory में decrypt करके stdout पर print करता है ताकि सीधे अन्य tools को stdin पर pipe किया जा सके। - Clean up:
ctg cleanlocal repo से सभी decrypted secrets हटा देता है ताकि आप अपने AI agents को थोड़ी कम चिंता के साथ चला सकें। - Supports jj and non-git directories:
ctg initकिसी भी directory को secret store में बदल देता है। - Sync with any provider: किसी भी API वाले provider को upstream के रूप में configure करें, और
git pull/diff/pushकी तरहctg pull/diff/pushका उपयोग शुरू करें। - Sync with any device: cottage से encrypt किए गए और git repo में प्रबंधित secrets को Cottage Sync के साथ विभिन्न devices पर sync किया जा सकता है।
Installation
# rust: cargo-binstall/cargo
cargo binstall --locked cottage
cargo install --locked cottage
# python: pip/uv/uvx
pip install cottage
uv pip install cottage
uvx --from cottage ctg --version
# node: yarn/pnpm/npx
yarn global add @sayanarijit/cottage
pnpm add -g @sayanarijit/cottage
npx -p @sayanarijit/cottage ctg --version
Docker images के रूप में भी उपलब्ध है:
# Docker
docker run --rm -v $PWD:/app sayanarijit/cottage --version
# Podman
podman run --rm -v $PWD:/app quay.io/sayanarijit/cottage --version
या GitHub से नवीनतम release डाउनलोड करें।
Editor Integrations
VS Code Extension
ctg install करने, Copilot safety hooks जोड़ने, Explorer से files encrypt करने, और editor workflow के माध्यम से .cott.age files खोलने के लिए Cottage VS Code extension का उपयोग करें।
इसे Visual Studio Marketplace से install करें, या vscode-plugin-cottage से locally build और install करें।
Cursor and Eclipse Extension
VSX file डाउनलोड करें और इसे अपने Cursor या Eclipse IDE में install करें। यह VS Code extension की तरह ही काम करता है।
Vim Plugin
Vim या Neovim से secrets को encrypt/decrypt करने के लिए cottage.vim plugin का उपयोग करें।
AI Agent Integrations
नीचे दिए गए सभी integrations AI agents को सीधे ctg/ctgx चलाने और secret files को देखने या संपादित करने से रोकते हैं: .cottage/ के अंदर कुछ भी, कोई भी *.cott.* file (encrypted *.cott.age blobs और redacted *.cott.toml previews), और कोई भी decrypted file जिसका disk पर अभी भी *.cott.age counterpart मौजूद है।
Claude Code Integration
यदि आप Claude Code का उपयोग कर रहे हैं, तो secrets वाले अपने repos में .claude/settings.json और .claude/hooks/deny-secrets.py जोड़ें ताकि Claude Code sessions secrets को सुरक्षित रूप से संभालें, या claude-plugin-cottage plugin install करें।
GitHub Copilot Integration
यदि आप VS Code में GitHub Copilot का उपयोग कर रहे हैं, तो secrets वाले अपने repos में .github/hooks/ctg-policy.json और .github/hooks/scripts/deny_ctg_command.py जोड़ें ताकि Copilot sessions decrypted files को साफ़ करें, सीधे ctg shell commands को block करें, और secret files तक पहुँच को block करें, या इसे VS Code से सेट करने के लिए vscode-plugin-cottage extension install करें।
VS Code .claude/settings.json hook definitions को भी load करता है। यदि आप एक ही repo में Claude और Copilot दोनों hook files रखते हैं, तो सुनिश्चित करें कि आप गलती से एक ही cleanup hook दो बार न चलाएँ।
Codex Integration
यदि आप Codex का उपयोग कर रहे हैं, तो secrets वाले अपने repos में .codex/hooks.json और .codex/hooks/deny-ctg.py जोड़ें ताकि Codex sessions secrets को सुरक्षित रूप से संभालें, या codex-plugin-cottage plugin install करें।
Codex को चलने से पहले local hooks की समीक्षा आवश्यक है। files जोड़ने के बाद, repo में Codex शुरू करें और project hooks की समीक्षा और trust करने के लिए /hooks का उपयोग करें।
Antigravity (agy) Integration
यदि आप Antigravity (agy) का उपयोग कर रहे हैं, तो secrets वाले अपने repos में .agents/hooks.json और .agents/scripts/deny-ctg.py जोड़ें ताकि Antigravity sessions secrets को सुरक्षित रूप से संभालें, या agy-plugin-cottage plugin install करें।
Cursor Integration
यदि आप Cursor का उपयोग कर रहे हैं, तो secrets वाले अपने repos में .cursor/hooks.json, .cursor/hooks/deny-ctg.py, .cursor/hooks/deny-read-secrets.py, .cursor/rules/deny-ctg.mdc, और .cursorignore जोड़ें ताकि Cursor sessions secrets को सुरक्षित रूप से संभालें।
Cursor में hooks को पहले enable करना आवश्यक है। Cursor Settings > Hooks खोलें और hooks enable करें, फिर agent session को restart करें ताकि project hooks प्रभावी हों। .cursorignore इसके अतिरिक्त secret files को Cursor की indexing और Agent के context से बाहर रखता है।
Quick Start
Project init करें:
mkdir project && cd project
git init # Optional, cottage works better with git but it's not required
ctg init # Sets up the .cottage directory and necessary files
tree -a
# .
# ├ .cottage/ <- Auto-generated by `ctg init`
# │ ├ identity <- Your private key, keep it safe. Move it to `~/.config/cottage/identity` to use it globally, or replace it with a soft link to one of your existing private keys.
# │ └ recipients/ <- This is where your team keeps the public keys of all the recipients.
# │ └ sayanarijit <- Your public key. Commit it. To use an existing public key, just copy (don't softlink) that key here.
# ├ .git/...
# ├ .gitattributes <- Added `*.cott.age binary linguist-generated filter=cottage-encrypted -diff` to avoid polluting git diff
# └ .gitignore <- Added `/.cottage/identity` for obvious reasons
# You can run `ctg clean --all` anytime to clean up everything cottage ever did.
एक secret बनाएँ या संपादित करें:
# `ctg edit` decrypts the file before opening in $EDITOR and re-encrypts upon save.
# If the decrypted file was not present on disk before running `ctg edit`, it is cleaned up afterwards.
# If it was already present, it is kept on disk.
ctg edit secret.yml
# Use `--clean` with `ctg edit` or `ctg encrypt` to ensure decrypted files are deleted even if present before
ctg edit secret.yml --clean # Opens in $EDITOR, encrypts on save, and cleans up
ctg encrypt secret.yml --clean # Encrypts secret.yml and cleans up
# encrypt secret.yml
# into secret.yml.cott.age
# edit secret.yml.cott.toml
# edit .gitignore
# delete secret.yml
Decrypted secrets के साथ एक command चलाएँ:
cat secret.yml
# cat: secret.yml: No such file or directory
# `ctg run` (or shortcut `ctgx`) decrypts secrets before running the command.
# If the decrypted files were not present on disk beforehand, they are automatically cleaned up after the command finishes.
# If they were already present beforehand, they are kept on disk.
ctg run -- kubectl apply -f secret.yml # decrypts secret.yml.cott.age to secret.yml and runs the command
ctg run -- kubectl apply -f secret.yml.cott.age # also replaces the path argument with the decrypted file path
ctg run -- kubectl apply -f . # decrypts all .cott.age files in . and runs the command
ctg run -- ./deploy.sh # decrypts all .cott.age files in repo and runs the command
cat secret.yml
# cat: secret.yml: No such file or directory
# Use `--clean` to ensure decrypted files are cleaned up even if they were present before
ctg run --clean ./deploy.sh
या shortcut का उपयोग करें:
ctgx -- ./deploy.sh
ctgx --clean -- ./deploy.sh
Decrypted secret को disk पर लिखे बिना पढ़ें और pipe करें:
ctg cat secret.yml.cott.age
ctg cat secret.yml | kubectl apply -f -
ctg cat .env.prod | docker run --rm --env-file /dev/stdin my-image:latest
Secrets को environment variables के रूप में inject करके command चलाएँ, बिना disk पर लिखे:
ctg env -- ./deploy.sh # Export secrets from .env.cott.age (default) without writing them to disk, then run deploy.sh
ctg env -F .env.prod.cott.age -- ./deploy.sh # exports from .env.prod.cott.age instead of .env.cott.age
ctg env -F secrets.json.cott.age -- printenv COTTAGE_SECRET # Also supports non-dotenv files.
GitOps
अपने secrets को team members के साथ शेयर करने के लिए, बस git repo में push करें।
git add .
git commit -m "Add secret.yml"
git push origin main
अपने साथियों से कहें कि वे अपनी public keys .cottage/recipients में जोड़ें और
परिवर्तन push करें। फिर आप pull करके उनके लिए secrets को फिर से encrypt कर सकते हैं।
git pull origin main
ctg decrypt --skip-verify-recipients # Decrypt missing secrets for re-encryption
ctg encrypt # Re-encrypt all secrets
# encrypt secret.yml
# into secret.yml.cott.age
# edit secret.yml.cott.toml
ctg clean # optional
# delete secret.yml
# review changes, commit and push
git add .
git commit -m "Add new recipient to secrets"
git push origin main
अब आपके साथी नवीनतम परिवर्तन pull कर सकते हैं और स्वयं secrets decrypt कर सकते हैं।
Git Hooks
आप commit से पहले secrets को स्वचालित रूप से check/encrypt करने और checkout के बाद decrypt करने के लिए git hooks सेट करने हेतु prek या pre-commit का उपयोग कर सकते हैं।
यहाँ उदाहरण prek configuration देखें।
prek.toml file जोड़ने के बाद, चलाएँ:
prek install
prek install --hook-type post-checkout
prek install --hook-type post-merge
prek install --hook-type post-rewrite
Access Control
Rules
Metadata file में, आप annotate कर सकते हैं कि secret किन recipients के लिए encrypt किया जाना चाहिए। यह आपको विभिन्न environments (जैसे staging vs production) के लिए अलग-अलग secrets रखने और उन्हें केवल संबंधित recipients के लिए encrypt करने की सुविधा देता है।
# secret.yml.cott.toml
[secret]
allow = ["sayanarijit"] # Only encrypt for sayanarijit
# secret.yml.cott.toml
[secret]
deny = ["sayanarijit"] # Encrypt for everyone except sayanarijit
# secret.yml.cott.toml
[secret]
allow = ["env/staging/*"] # Supports glob patterns, only encrypt for recipients in env/staging
deny = ["env/staging/badservice"] # Encrypt for everyone in env/staging except badservice
Deny rules, allow rules पर प्राथमिकता लेते हैं।
अधिक जानकारी के लिए metadata specification देखें।
Verification
Tampering रोकने के लिए, आप CI में ctg verify चला सकते हैं ताकि यह सत्यापित हो सके कि encrypted secrets और recipient lists metadata rules से मेल खाते हैं।
# .github/workflows/cottage-verify.yml
name: Cottage Verify
on: [push, pull_request]
permissions:
contents: read
jobs:
verify-secrets:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Verify secrets
run: docker run --rm -v "${{ github.workspace }}:/app" ghcr.io/sayanarijit/cottage verify
Any Provider as Upstream
cottage के साथ, आप secrets को किसी भी API वाले provider के साथ sync कर सकते हैं, केवल git ही नहीं।
इसके लिए, project root में cottage.toml नाम की एक file बनाएँ और upstream settings configure करें।
यहाँ उदाहरण cottage.toml देखें और यहाँ secret specific upstream configuration देखें।
यहाँ एक उदाहरण plugin implementation देखें।
Workflow git के समान है, लेकिन git pull और git push के बजाय, आप configured upstream के साथ secrets sync करने के लिए ctg pull और ctg push चलाते हैं।
उदाहरण:
# Pull latest changes into local encrypted secrets
# Similar to `git pull origin`
ctg pull myvault
# Compare diff with local decrypted secrets
ctg diff
# Sync local decrypted secrets with local encrypted secrets
ctg sync
# Push changes from local encrypted secrets to upstream
# Similar to `git push origin main`
ctg push myvault
अधिक जानकारी के लिए upstream configuration specification देखें।
Example plugins
Cottage आपके secrets को sync करने के लिए विभिन्न plugin providers का समर्थन करता है। तैयार-से-उपयोग plugin scripts examples/plugins directory में उपलब्ध हैं:
- 1Password
- AWS Secrets Manager
- Azure Key Vault
- Bitwarden
- Dashlane
- Doppler
- ejson
- GitHub Secrets
- Google Cloud Secret Manager
- HashiCorp Vault (also see Vault in Kubernetes)
- Keeper Security
- KeePass (Passhole)
- LastPass
- pass (password-store)
- Proton Pass
- System Keyring
- Zoho Vault
Sync with any device
अपने secrets को अपने devices पर sync करने और CLI की आवश्यकता के बिना ब्राउज़ करने के लिए Cottage Sync का उपयोग करें।
Learn More
अधिक उपयोग उदाहरणों के लिए examples directory देखें।
Troubleshooting
# See debug logs with -v, -vv or -vvv
ctg run -vvv -- ./deploy.sh
Comparison
age vs Other Encryption
age सुरक्षित file encryption के लिए अनुकूलित एक आधुनिक, सरल algorithm का उपयोग करता है, जिसमें usability और न्यूनतम attack surface पर ध्यान केंद्रित है। यह SSH RSA और Ed25519 keys का भी समर्थन करता है, हालाँकि अलग-अलग उद्देश्यों और scopes के लिए अलग-अलग keys का उपयोग करने की सलाह दी जाती है।
cottage vs SOPS
हालाँकि SOPS और cottage में कई overlapping features हैं, cottage के निम्नलिखित लाभ हैं:
- unencrypted secrets कभी भी git में commit न हों, यह सुनिश्चित करने के लिए .gitignore को स्वतः प्रबंधित करता है।
- Encrypted secrets के pure age encrypted .age files होने से, tools के व्यापक ecosystem के साथ बेहतर interoperability संभव होती है।
- Cleaner diffs - SOPS के विपरीत, जो हर secret के हर value के लिए diffs जनरेट करता है, भले ही वास्तविक परिवर्तन केवल एक recipient जोड़ना/हटाना हो, cottage प्रति file केवल एक diff जनरेट करता है, जो recipients checksum में परिवर्तन को स्पष्ट रूप से इंगित करता है।
cottage vs dotenvx
cottage ने ctg env API dotenvx से उधार ली है।
- केवल dotenv files ही नहीं, किसी भी file type का समर्थन करता है।
- एक repo में कई secrets प्रबंधित करता है।
- विशिष्ट recipients के लिए secrets encrypt करने के लिए access control rules।
- Cleaner diffs - देखें cottage vs SOPS।
cottage vs agebox
agebox मूल philosophy में cottage के बहुत समान है, लेकिन इसमें कई features की कमी है।
