SPIKE

Keep Your Secrets… Secret

SPIKE helps DevOps, SREs, and SysAdmins manage secrets across distributed systems with confidence. Literally helps teams #sleepmore.

SPIKE Screenshot

Built for Zero Trust

SPIFFE-Native Secrets Store

SPIKE has minimal footprint; is easy to run; and is secured by the same identity framework that powers Kubernetes: SPIFFE.

Fingerprint Lock Privacy Icon
SPIFFE Identity Control Plane

Leverage SPIFFE workload identities for secure mTLS connectivity and authentication—no static credentials or API keys needed.

Learn more

Browser Code 1 Icon
SPIKE Command Line Interface

Manage secrets, policies, and operations directly from the terminal, giving you a simple, scriptable way to work with secrets.

Learn more

Chat Bubble Video Call Square Icon
Presentations & Demos

See SPIKE in action—from introductions to advanced features. Watch walkthroughs and world demos showcasing SPIFFE-powered secrets management.

Learn more

Secrets Without the Ceremony

No Unseal Key? No Problem

No more lost keys. No more 3 a.m. wake-up calls—SPIKE uses SPIFFE identities to keep your secrets always available, always secure.

App screenshot
Fingerprint Check Validate Icon Identity-driven secrets.
Forget static keys. SPIKE secures secrets with SPIFFE Verifiable Identity Documents—dynamic and workload-bound.
Padlock Key Icon No unseal keys.
No root key to lose. No manual unsealing. Secrets are available without a single point of failure.
Perspective Warp Transform Distort Icon Federation-ready.
Share secrets securely across clusters with built-in support for SPIFFE trust bundles.
Sail Ship Icon Lightweight by design.
A minimalist core that avoids operational overhead—deploy it fast, run it anywhere.
Document Certificate Icon Policy-driven access.
Fine-grained policies define which workload can access which secret. No all-or-nothing sharing.
Encrypted Lock Icon Zero trust with SPIFFE.
SPIKE relies on SPIFFE as its identity control plane, providing secure, cryptographic workload identities.

Built on Strong Foundations

When the Creators Take Notice

“It is really cool to see a new secret store built on top of SPIFFE natively. This is a great way to show how a common production identity framework can make other things much simpler and automated.”
Joe Beda, creator of SPIFFE, co-creator of Kubernetes

Join the SPIFFE-Native Future of Secrets

SPIKE is an open source project built on the SPIFFE identity control plane: Secure, federated, and designed for modern workloads.