EN
返回档案库

档案库 · 开发与企业工具 · 产品决策 · 2017–2025

EnvKey的零信任赌注:2022年开源v2,2025年云端关停

YC W18毕业的密钥管理器赌开发人员接受UX成本,让任何主机都看不到明文;v2于2022年以MIT协议开源,但云端服务在2025年关闭

EnvKey

它在赌什么开发团队会选择主机永远看不到明文的密钥管理器;以MIT协议开源v2可以证明这一点,并为付费云服务带来收入已经没了

做的是什么生意

EnvKey is an end-to-end encrypted configuration and secrets manager: it stores an organization's API keys, encryption keys, credentials and config, pushes them to servers, scripts and tests through a CLI (envkey-source), and sells managed Cloud and Enterprise Self-Hosted tiers.

起因

The founder (danenania) posted the first version of EnvKey to Hacker News in 2017 and went through Y Combinator's W18 batch. By 2022 EnvKey was an end-to-end encrypted config and secrets manager protecting API keys, credentials and config across servers, scripts and tests, with a spreadsheet-like UI plus a developer CLI that runs any program with the latest environment variables.

经过

The v2 release on 2022-03-30 made the core fully open source (MIT) and self-hostable, added device-based authorization with a free Cloud tier (20 user devices, 40 server keys), and sold commercial Cloud and Enterprise Self-Hosted tiers. In the thread the founder argued against UX-first cloud rivals like Doppler and host-trusted tools like HashiCorp Vault, citing incidents like Okta; customers pushed back that the v1→v2 migration forced manual key re-imports and that new pricing could multiply a small agency's bill roughly 14x, to which he promised adjustments.

结果

The commercial Cloud was wound down: the GitHub README, still current as of 2026-09-06, announces that as of 2024-08-01 EnvKey Cloud began a six-month wind-down with new registrations disabled and shutdown on 2025-02-01; the MIT-licensed code remains public.

背景

EnvKey是一款端到端加密的配置和密钥管理器:它存储API密钥、加密密钥、凭证和配置,并通过CLI将之推送到服务器、脚本和测试环境,同时提供类电子表格的UI来管理环境。

创始人于2017年在Hacker News上发布了第一版,并参加了Y Combinator的W18批次。EnvKey的赌注是开发团队会采用主机永远看不到明文的环境——接受更复杂的UX来换取不信任任何服务器、云供应商员工或浏览器对密钥的处理。

2022年3月30日发布的v2将核心代码以MIT协议开源,支持自托管,增加了基于设备的授权和免费的云服务层级,并保留了付费的云服务和企业自托管产品。发布帖获得225分和65条评论,创始人捍卫客户端NaCl加密,以对抗注重便利性的Doppler和信任主机的Vault,同时客户抱怨迁移困难和可能约14倍的价格上涨。

结局是:EnvKey的GitHub README宣布云服务于2024年8月1日开始为期六个月的关停,禁止新注册,并于2025年2月1日关闭。截至2026年9月6日,MIT许可的客户端和代码仓库仍然公开。

这件事要成立,得有什么

  • 密钥散落——密钥在Slack、.env文件和CI之间复制——是一个真实且不断增长的痛点,每个团队都会遇到,因此该类别有需求。
  • 不信任主机,不通过浏览器处理,这些都是对抗注重UX的Doppler和信任主机的Vault的合理差异性。
  • 以MIT协议开源让持怀疑态度的开发人员能在付费之前审计加密,将安全声明变为可检查的证据。
  • 托管的云服务和企业自托管为从免费和开源采用到收入提供了路径。

可借鉴之处

零信任承诺只有在客户能低成本验证时才会得到加强;开源客户端是证明,但重新定价惩罚小型现有团队可能会让竞争对手获得迁移潮。

后续进展

截至2026年9月6日,EnvKey的GitHub README声明,EnvKey Cloud于2024年8月1日开始为期六个月的关停,禁止新注册,并于2025年2月1日关闭,通知指向详细的关停公告以帮助迁移。该仓库和MIT许可的客户端仍然公开,因此开源核心在公司停运后依然存在。

资料来源

发现哪里写错了?告诉我们。

轮到你了

你刚读完一家。说说你在做什么,看看谁在赌同一件事。

免费账号 · 3 次免费提问 · 不用绑卡

相关案例