# Installer credstash avec Homebrew, Nix

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de credstash pour les workflows d'agents IA.

## installation

```sh
sudo av install brew:credstash
```

Commandes d'installation supplémentaires:

### macOS

- Homebrew (100%):

```sh
brew install credstash
```

  Preuve: local Homebrew formula metadata

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#credstash
```

  Preuve: nixpkgs package indexes: credstash from https://raw.githubusercontent.com/NixOS/nixpkgs/master/pkgs/top-level/all-packages.nix

## Faits du paquet

- **Clé du paquet:** brew:credstash
- **Gestionnaire de paquets:** Homebrew
- **Version:** 1.17.1
- **Résumé source:** Little utility for managing credentials in the cloud
- **Page d'accueil:** <https://github.com/fugue/credstash>
- **Dépôt:** <https://github.com/fugue/credstash>
- **Dernière mise à jour:** 2026-05-12T19:39:56Z
- **Généré:** 2026-08-03T19:37:03+00:00

## exécutables

- credstash (alias)
- credstash.py (alias)

## Comportement d'installation

- Bouteille: non disponible

## Version et fraîcheur

- page générée: 2026-08-03
- version du gestionnaire: 1.17.1
## Historique du projet et usages

CredStash is a small command-line and Python-library tool for storing secrets with AWS KMS and DynamoDB. It targets teams that want a simple credential store without operating a larger dedicated secrets-management service.

### Historique du projet

The README frames CredStash as a response to common ad hoc secret-handling practices such as copying secrets files around a fleet or committing secrets to source control. Its design uses KMS for key wrapping and master-key storage, DynamoDB for encrypted credential records, and AWS IAM for access control.

### Historique d'adoption

The project grew beyond a single Python command-line tool through compatible implementations in Java, Ruby, Scala, PHP, Node.js, Go, C#, Erlang, Rust, and Kubernetes-related tooling listed by the upstream README. Later changelog entries also added operational features such as tags, putall, keys, session handling, YAML and dotenv-style output, and multiple-region KMS/DynamoDB support.

### Modes d'utilisation

The standard setup is to install credstash, create or choose a KMS key, ensure AWS credentials are available to boto or botocore, and run credstash setup to create the DynamoDB table. Users then put, get, list, delete, and bulk-fetch versioned secrets from shell scripts or deployment workflows.

### Pourquoi les passionnés de paquets s'y intéressent

For package maintainers, CredStash is notable as an AWS-backed secrets CLI that keeps its runtime footprint small but relies on cloud-side primitives. Its Homebrew formula exposes a Python security tool to macOS operators who may otherwise install it from pip.

### Chronologie

- 2015-12: README documents an auto-versioning behavior change and migration path for older unpadded integer versions
- 1.14.0: Added wildcard get, keys, putall, and pagination fixes
- 1.15.0: Improved packaging and added credential comments
- 1.16.0: Added autoversion API support, DynamoDB table tagging, environment-variable table selection, and custom DynamoDB/KMS sessions
- 1.17.0: Added independent KMS-region selection for DynamoDB Global Tables-style deployments

### Related projects

- The README lists compatible CredStash implementations for Java, Ruby, Scala, PHP, Node.js, Go, C#, Erlang, Rust, and Kubernetes.

### Sources

- <https://github.com/fugue/credstash#readme>
- <https://github.com/fugue/credstash/blob/master/changelog.md>


## Notes de sécurité

infrastructure mutation or orchestration signal.

- **Risque Geiger:** orange / moyen
- infrastructure mutation or orchestration signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: ~/.aws/config

## Credential files

- Unix: ~/.aws/credentials
## Autres enregistrements de gestionnaires de paquets

- Nix - credstash: normalized package name match | nixpkgs package indexes: credstash from https://raw.githubusercontent.com/NixOS/nixpkgs/master/pkgs/top-level/all-packages.nix


## Combined YAML source

View the package source record on GitHub. [combined/credstash.yml](https://github.com/mxcl/pkgdb/blob/main/combined/credstash.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
