secs-man
Encrypt and back up secrets with interoperable age archives
TLDR
SYNOPSIS
secs-man subcommand [options] [paths]
DESCRIPTION
secs-man is a command-line secrets manager focused on tool-independent backups. Files are encrypted with age using a passphrase you enter at export and import time; the tool never reads the passphrase from a file, argument, or environment variable. Each export creates a timestamped snapshot of `.age`-suffixed ciphertext files plus companion sha256sums manifests.A plaintext .secrets-manifest at the root of the secrets directory lists which paths to manage. Each entry may specify owner and mode permissions applied on import. The design goal is recoverability without secs-man itself: decryption and restore can be reproduced manually with age, cp, chmod, and chown.The optional secs-man-ssh shell script (shipped separately in the repository) exports from or imports to remote hosts over SSH without passing the passphrase through the remote machine.
PARAMETERS
export secrets-dir export-endpoint
Encrypt every file listed in `.secrets-manifest` under secrets-dir with age and write a timestamped snapshot under export-endpoint. Passphrase is prompted interactively.import export-endpoint secrets-dir
Decrypt and restore secrets from the latest snapshot (or a specific snapshot path) into secrets-dir, applying owner and mode from the manifest.verify-export export-endpoint
Check SHA-256 checksums for every file in one or all snapshots under export-endpoint.--pick paths...
On import, restore only the listed manifest-relative paths.--from-plaintext / --skip-chown-chmod
Advanced flags used by the companion secs-man-ssh script for remote workflows.
CONFIGURATION
.secrets-manifest — plaintext file at the secrets root listing managed paths (relative), optional owner, and optional mode. See the upstream `.secrets-manifest.example` for syntax. File paths cannot contain whitespace.
CAVEATS
Not published to crates.io, nixpkgs, or distro repos; install via cargo install --git, nix run, or a Nix flake. sudo is required when the manifest assigns owners other than the invoking user. Export snapshots are never auto-deleted — rotate or remove old snapshots manually when backing up decrypting secrets (disk keys, age identities). Integrity checks run automatically on every export; verify-export is for auditing older snapshots.
HISTORY
secs-man was written in Rust by Fran314 and released as secrets-manager-rs under the AGPL-3.0 license, emphasizing long-term accessibility through standard age encryption rather than proprietary formats.
