KeyVault Manager is a macOS desktop application built with Fyne for managing Azure Key Vault secrets across multiple subscriptions.
The app provides an easy-to-use graphical interface that wraps the Azure CLI (az), allowing you to quickly browse vaults, read secrets, view history, and manage secrets without remembering complex terminal commands.
- Subscription Management: Automatically loads available Azure subscriptions and lets you seamlessly switch between them.
- Vault Exploring: Lists Key Vaults available in the selected subscription.
- Secret Management:
- View all secrets within a selected Key Vault.
- Create and push new secrets easily.
- View the revision history of individual secrets.
- macOS Native Feel: Bundled as a
.appmaking it easy to run securely like any native application.
Because KeyVault Manager uses Azure CLI commands under the hood, you need to have the Azure CLI installed and authenticated.
- Install Azure CLI:
brew update && brew install azure-cli - Authenticate:
az login
-
Clone the repository:
git clone https://github.com/eugenegoncharuk/keyvault-manager.git cd keyvault-manager -
Install dependencies (assuming Go 1.21+ is installed):
go mod download
-
Run the App:
go run .
To build the macOS .app bundle locally:
- Install the
fyneCLI tool:go install fyne.io/fyne/v2/cmd/fyne@latest
- Package the app:
fyne package -os darwin -icon Icon.png
This will generate KeyVault Manager.app in your project folder, which you can drag to your Applications folder or distribute.
When an application gets downloaded from any source other than those that Apple seems suited, the application gets an extended attribute "com.apple.Quarantine". This triggers the message: " is damaged and can't be opened..."
Remove the attribute and you can launch the application. To do this, open a console and type: $ xattr -c <path/to/application.app>
Now you can start the App.
This repository is configured with a GitHub Actions workflow that automatically builds and releases the macOS .app bundle whenever a new tag (e.g., v1.0.0) is pushed to the repository. The release will contain a .tar.gz archive with the built application, which can be downloaded directly from the GitHub Releases page.