# 使用 Homebrew, Nix 安装 credstash

查看 credstash 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:credstash
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install credstash
```

  证据: local Homebrew formula metadata

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#credstash
```

  证据: nixpkgs package indexes: credstash from https://raw.githubusercontent.com/NixOS/nixpkgs/master/pkgs/top-level/all-packages.nix

## 软件包事实

- **软件包键:** brew:credstash
- **软件包管理器:** Homebrew
- **版本:** 1.17.1
- **来源摘要:** Little utility for managing credentials in the cloud
- **主页:** <https://github.com/fugue/credstash>
- **仓库:** <https://github.com/fugue/credstash>
- **最后更新:** 2026-05-12T19:39:56Z
- **已生成:** 2026-08-03T19:37:03+00:00

## 可执行文件

- credstash (别名)
- credstash.py (别名)

## 安装行为

- Bottle: 不可用

## 版本和新鲜度

- 页面生成时间: 2026-08-03
- 管理器版本: 1.17.1
## 项目历史与用法

CredStash is a small command-line and Python-library tool for storing secrets with AWS KMS and DynamoDB. It targets teams that want a simple credential store without operating a larger dedicated secrets-management service.

### 项目历史

The README frames CredStash as a response to common ad hoc secret-handling practices such as copying secrets files around a fleet or committing secrets to source control. Its design uses KMS for key wrapping and master-key storage, DynamoDB for encrypted credential records, and AWS IAM for access control.

### 采用历史

The project grew beyond a single Python command-line tool through compatible implementations in Java, Ruby, Scala, PHP, Node.js, Go, C#, Erlang, Rust, and Kubernetes-related tooling listed by the upstream README. Later changelog entries also added operational features such as tags, putall, keys, session handling, YAML and dotenv-style output, and multiple-region KMS/DynamoDB support.

### 使用方式

The standard setup is to install credstash, create or choose a KMS key, ensure AWS credentials are available to boto or botocore, and run credstash setup to create the DynamoDB table. Users then put, get, list, delete, and bulk-fetch versioned secrets from shell scripts or deployment workflows.

### 为什么软件包爱好者会关心

For package maintainers, CredStash is notable as an AWS-backed secrets CLI that keeps its runtime footprint small but relies on cloud-side primitives. Its Homebrew formula exposes a Python security tool to macOS operators who may otherwise install it from pip.

### 时间线

- 2015-12: README documents an auto-versioning behavior change and migration path for older unpadded integer versions
- 1.14.0: Added wildcard get, keys, putall, and pagination fixes
- 1.15.0: Improved packaging and added credential comments
- 1.16.0: Added autoversion API support, DynamoDB table tagging, environment-variable table selection, and custom DynamoDB/KMS sessions
- 1.17.0: Added independent KMS-region selection for DynamoDB Global Tables-style deployments

### Related projects

- The README lists compatible CredStash implementations for Java, Ruby, Scala, PHP, Node.js, Go, C#, Erlang, Rust, and Kubernetes.

### 来源

- <https://github.com/fugue/credstash#readme>
- <https://github.com/fugue/credstash/blob/master/changelog.md>


## 安全说明

infrastructure mutation or orchestration signal.

- **Geiger 风险:** orange / 中
- infrastructure mutation or orchestration signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: ~/.aws/config

## Credential files

- Unix: ~/.aws/credentials
## 其他软件包管理器记录

- Nix - credstash: normalized package name match | nixpkgs package indexes: credstash from https://raw.githubusercontent.com/NixOS/nixpkgs/master/pkgs/top-level/all-packages.nix


## Combined YAML source

View the package source record on GitHub. [combined/credstash.yml](https://github.com/mxcl/pkgdb/blob/main/combined/credstash.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
