Back to Open Science Labs
GSoC 2026

Implement Enterprise Security & Provider Ecosystem Expansion

Swarm external secrets project enables Docker Swarm services to consume secrets from external secret managers, but it still lacks several features needed for secure and production ready deployments. At present, some providers rely on older credential models, transport security can be improved, and support for newer secret backends and modern authentication workflows is limited. This project aims to close those gaps by making the plugin more secure, extensible, and operationally reliable. The proposed work will focus on adding modern identity-based authentication methods such as JWT and OIDC flows for Vault and related providers, improving TLS and mTLS support with better CA bundle handling, and strengthening secret lifecycle support such as version awareness and rotation compatibility. In parallel, the project will expand provider support by integrating additional backends such as 1Password, Doppler, and Infisical. The deliverables will include secure authentication improvements, stronger transport security, new provider implementations, improved tests and documentation, and better observability so that swarm-external-secrets becomes a more enterprise-ready secret management solution for Docker Swarm.

Project details

Contributor

Atharva Mhaske

Mentors

Not available

Technologies

Not listed in the archive