PKI and Secrets Management: Simplified, Automated, Secure

Issue and manage certificates, protect secrets, and secure cryptographic keys with HSM-backed workflows —built for Kubernetes

One platform for certificate and secret operations

Most teams run PKI, secrets, and key management in disconnected tools. KeyAuthority centralizes cryptographic operations so security and platform teams can move faster with policy, traceability, and automation.

Main features

Private CAs & PKI orchestration

Centralized management of your certificate lifecycle. Automate issuance, renewal, and revocation across multiple CAs with fine-grained control and compliance-ready audit trails.

Secrets management

Secure storage for API keys, passwords, and configuration data with role-based access controls, encryption at rest, and visibility into access activity.

Hardware Security Module integration

Enterprise-grade key protection through PKCS#11. Keep sensitive cryptographic material in tamper-resistant hardware while retaining automated workflows.

Cloud-native & DevOps ready

Built for Kubernetes and modern delivery pipelines. Integrate with GitLab CI/CD, federate identities through OIDC and Keycloak, deploy with Helm, and scale horizontally.

Security workflows, expressed in code

Connect Kubernetes certificate issuance and CI/CD secret access to the tools your teams already use

CERTIFICATES

Issue TLS with cert-manager

KUBERNETES

Point an ACME Issuer at your KeyAuthority signer and let cert-manager handle certificate requests and renewals.

Kubernetes ClusterIssuer and Ingress configured for certificate issuance
SECRETS

Federate GitLab CI access

GITLAB CI/CD

Exchange a GitLab job ID token for a KeyAuthority client token, then use that token for authorized API access to secrets.

GitLab deployment job injecting PostgreSQL credentials from KeyAuthority

Know more

FAQ

Can I use it for free?
Yes. You can deploy and use it without cost, with optional paid features and support available.
How can I deploy it in my Kubernetes cluster?
Use the KeyAuthority Helm chart published on ArtifactHub.
Is Kubernetes required?
No, but the platform is optimized for Kubernetes deployments.
How do I automate certificate renewal?
KeyAuthority integrates with cert-manager to automate certificate lifecycle management.
How can I use secrets with GitLab CI/CD?
KeyAuthority exposes APIs that allow GitLab runners and other CI/CD workloads to access secrets.
Does it integrate with our identity provider?
OIDC federation is supported, with Keycloak as a common integration pattern.
Do you provide audit logs for compliance?
Yes. Access and lifecycle events are recorded for traceability and audits.
Can we use our existing HSM?
Yes. PKCS#11-compatible HSM integrations are supported.