Fnox, a Secret Manager That Pairs Well with Mise
Posted2 months agoActive2 months ago
github.comTechstory
calmmixed
Debate
60/100
Secret ManagementDevops ToolsSecurity
Key topics
Secret Management
Devops Tools
Security
Fnox is a new secret manager that pairs well with mise, a dev environment management tool, sparking discussion on its design and potential alternatives.
Snapshot generated from the HN discussion
Discussion Activity
Moderate engagementFirst comment
1h
Peak period
10
12-18h
Avg / period
3.2
Comment distribution29 data points
Loading chart...
Based on 29 loaded comments
Key moments
- 01Story posted
Oct 27, 2025 at 12:29 PM EDT
2 months ago
Step 01 - 02First comment
Oct 27, 2025 at 1:56 PM EDT
1h after posting
Step 02 - 03Peak activity
10 comments in 12-18h
Hottest window of the conversation
Step 03 - 04Latest activity
Oct 30, 2025 at 9:22 AM EDT
2 months ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
ID: 45722931Type: storyLast synced: 11/20/2025, 7:35:46 PM
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.
[0] https://hk.jdx.dev/
I'd probably say hk is the most challenging pre-commit manager to setup compared to its peers. That said, it's also the only one that can run hooks in parallel safely and deal with partially staged files where the others don't bother with these problems.
At least right now hk is good for folks that want the fastest and don't mind a bit of effort. Hopefully I can improve that and make it the best all-around.
I’m looking forward to trying fnox!
That’s just off the top of my head.
They both accept a list of files to work on, but the filter on hk gives you a full list of files that changed, so if a cs file and a tf file changes, both steps will fire with both the cs and the tf file
I think a small improvement might be adding a matched_files template sub that would only show the files that matched the glob rule. I also think an LSP integration for VSCode would go a long way. I could manage the first but the second might be pushing my limits
In this case, the user “jdx” has published an issue (a bug or feature development tracker) about a complimentary project, but you can still access the source code and documentation about “mise” by clicking on the hyperlink labelled “mise” at the top of the page.
https://asdf-vm.com
I've use mise happily for many months without using direnv or tasks, and everything I use it for works and is solid. Installs python, ruby, node, does the switching, does the shims, stays out of the way.
direnv and tasks and everything else mise can do is all opt-in.
Different people have different experiences and work on things in a very diverse scale. The existence of one thing does not obviate all other things.
# New person joins the team:
# 7. Team lead updates fnox.toml with new recipient
# Then re-encrypts all secrets:
fnox set DATABASE_URL "$(fnox get DATABASE_URL)" --provider age # ... repeat for all secrets
It's a bit surprising you have to manually do this, I'd imagine fnox already has knowledge of all the secrets and could do this automatically.
14 more comments available on Hacker News