env-master

env-master and Doppler

Doppler is the reference for usability: the environments-by-keys table, tidy integrations, a clear interface. We are both managed services, so the argument is not about where the data lives but about what you can find out regarding access to it.

What is known about every read

Reading a value here is a separate event in a separate audit stream, not a line in the general activity feed. The stream is hash-chained: an entry cannot be cut out after the fact and still have the chain add up, and the fingerprints are computed under a key different from the one that encrypts the data. That is our answer to “but do you look yourselves” — not a promise, but the fact that looking leaves a record.

How narrow the access is

An identity is scoped not to an environment but to a list of keys: the billing worker gets DB_*, not the whole of production. Plus restricted visibility — a value never shown to a person at all, neither in the interface nor on request; only a service fetches it.

What we took from them

One record with a visibility flag instead of two stores, and the environments table — those are good decisions worth copying. We added an audit trail of every read and identities scoped to key sets.

When to pick Doppler

Doppler is older, its integration catalogue is broader and its operating history longer — if that settles it, take it; we are younger and will not pretend otherwise. One more honest reason: we charge for services rather than seats, so a small team with a large number of services will find us more expensive.