0.x · one Go binary · self-hosted

Every environment
answers for itself.

Hikyo gives self-hosting teams one view of validated configuration and secrets. Every value is explicit: see what is set, catch what is missing, and require deliberate access before sensitive values move.

MPL-2.0. Active 0.x development. No enterprise-only directory.

PL platform/ payments-api
Example configuration matrix for three environments
Keydevelopmentstagingproduction
database 3
DATABASE_URL● set · secret● set · secret● set · secret
DATABASE_POOL_MAX✓ 10✓ 20Δ 40
DATABASE_SSLMODE✓ disable✓ verify-full✓ verify-full
payments 3
STRIPE_SECRET_KEY○ absent● set · secret● set · secret
STRIPE_WEBHOOK_SECRET○ absent● set · secret! required · absent
PAYMENTS_MOCK_PROVIDER✓ true✓ false○ absent (forbidden)
observability 2
LOG_LEVEL✓ debug✓ info✓ info
SENTRY_DSN○ absent● set · secret● set · secret
smtp 2all or none
SMTP_HOST○ absent✓ smtp.example.com✓ smtp.example.com
SMTP_PASSWORD○ absent! required · absent● set · secret

1required here, absent: publish refuses

2Δ draft, unpublished

3forbidden, correctly absent

  1. 1STRIPE_WEBHOOK_SECRET · productionrequired here, absent: publish refuses
  2. 2DATABASE_POOL_MAX · productionΔ draft, unpublished
  3. 3PAYMENTS_MOCK_PROVIDER · productionforbidden, correctly absent
example data set here absent secret set required, absent Δ draft forbidden

Built for infrastructure you own

GoSQLitePostgreSQLHelmOpenAPI

// one path from intent to runtime

Declare once. Decide per environment.

Hikyo separates the shape of a key from each environment's value, then keeps delivery inside the same authorization model.

  1. 01

    Declare the contract

    Choose config or secret, add validation, and state where the key is required.

    key create
  2. 02

    Set and review state

    Work in an explicit matrix where absence, invalid input, and pending changes stay visible.

    values set
  3. 03

    Deliver with intent

    Fetch at runtime, render for Compose, reconcile Kubernetes, or use a declared adapter.

    hikyo run

// explicit state, deliberate access

A dense surface that stays honest.

A growing key catalogue across several environments should stay scannable. Hikyo makes absence visible and keeps secret material behind a separate disclosure path.

Every environment answers for itself.

Values never fall through a hidden inheritance chain. Each cell is explicitly set or absent, so production cannot quietly borrow a development default.

▸ Flat values: no inheritance, no hidden fallback.

DATABASE_POOL_MAX · coverage
development10set ✓
staging20set ✓
production40set ✓

3 environments · 3 explicit values · 0 fallbacks

Revealing a secret is a ceremony.

Secrets stay masked until you deliberately re-authenticate. Reveal windows remask automatically, and clipboard copies become individual audited disclosures.

▸ Write-only replacement never needs the current plaintext.

STRIPE_SECRET_KEY · production
⌾ Re-authentication required protected environment
before••••••••••••
aftervalue written to ./stripe-keyremask 0:18

Invalid changes stop at write time.

Key declarations distinguish config from secrets and attach validation rules. Invalid values are refused, and a value required in an environment cannot be cleared there.

▸ The server validates the value and presence rule together.

SENTRY_DSN · production · clear
✓current value is setsecret
!clear requested in productionchange
✓presence rule is requiredrequired_in
×clear refused; value unchangedfail-closed

Delivery fails closed at the boundary.

A workload gets configuration through its scoped identity. Secret plaintext also requires the project machine-reveal opt-in and a reveal grant; otherwise delivery stops before the child starts.

▸ The happy path writes no plaintext file to the host disk.

hikyo run · production
# start a process with an authorized environmenthikyo run -- ./payments-api  ✓ identity verified  ✓ grant constrained to project + environment  ✓ config ready for the child process  → secret plaintext needs explicit machine reveal  ! inaccessible secret stops launch

// runs where you do

Own the keys. Own the data.

Self-hosting is the product, not a paid tier. Run one binary with its embedded web UI, choose SQLite or PostgreSQL, and hold the root key outside the datastore it protects.

runtime
One Go binary with an embedded web interface.
storage
SQLite or PostgreSQL, selected explicitly.
encryption
Envelope encryption with operator-held root key material.
deploy
A first-party Helm chart for Kubernetes and K3s.

// choose with the gaps visible

Different tools, different jobs.

Hikyo starts with explicit environment state and validated values. OpenBao leads on dynamic infrastructure credentials; Infisical and Phase pair broad delivery workflows with paid tiers.

Product capability comparison between Hikyo, OpenBao, Infisical, and Phase
CapabilityHikyofully openOpenBaoInfisicalPhase
Self-hosted✓✓✓✓
Fully open production path✓✓——
Config and secrets✓—✓✓
Explicit environment matrix✓×——
Value and presence validation✓×××
Workload plaintext delivery✓✓✓✓
Dynamic secrets✓✓AdvEE
Automated secret rotation◷ post-1.0✓ProPro
SCIM provisioning✓×EEEE
Native multi-node HA✓✓——
Application-level recovery✓—ProPro

✓ included— partial or indirect× unavailableAdv/Pro paid tierEE enterprise tier

Hikyo entries describe main-branch capabilities; the 1.0 roadmap records remaining release gates. Clocks mark post-1.0 work without a promised minor version. Other products were compared against public self-hosted documentation and plan availability on 25 August 2026: OpenBao,Infisical, and Phase.

// why hikyo exists

Operational capability should not be an enterprise upsell.

Secrets products often make audit, SSO, SCIM, or recovery the reason to upgrade. Hikyo keeps the production path in the same open repository under the Mozilla Public License 2.0.

The environment matrix is the core idea: explicit state you can inspect, disclosure you must intend, and refusals that name the safe next action.

No badge wall. No hidden operational tier. Infrastructure you can reason about.

Built in the open · MPL-2.0 · no /ee

// before you evaluate it

Questions worth answering plainly.

Hikyo is open, self-hosted, and still pre-1.0. These boundaries matter before you place it near real configuration or secret material.

Read the complete documentation
What problem does Hikyo solve?
Hikyo gives each environment an explicit value state. A key is set or absent, so production cannot silently inherit a development default.
Is Hikyo ready for a stable production rollout?
Hikyo is under active 0.x development and has not published its stable 1.0 release. Review the implementation-status ledger and deploy from a reviewed commit if you evaluate it today.
Does self-hosting require a Hikyo cloud account?
No Hikyo cloud account is required. You run the Go binary and embedded web UI on infrastructure you operate, with SQLite or PostgreSQL as the datastore.
When can a workload receive secret plaintext?
Only after an operator enables the project machine-reveal policy and grants that machine principal reveal access for the environment. Otherwise secret delivery refuses before the workload starts.
Where does Hikyo keep the root key?
The operator supplies root key material separately from the SQLite or PostgreSQL datastore. The self-hosting guide documents the supported custody options and startup checks.
Are production capabilities hidden in a paid edition?
Hikyo keeps its production path in the same MPL-2.0 repository. There is no separate enterprise-only implementation directory.

Config you can reason about.

Hikyo is under active 0.x development. Read the code, inspect the decisions, and follow the road to 1.0.