Pollen config
Secrets, managed.
Encrypted at rest. Injected at boot. Versioned. Your workloads never see a plaintext secret on disk.
Pollen secrets
The right secret, at the right boundary.
Secret references resolve inside the selected environment. The workload receives its values at the execution boundary.
DATABASE_URL••••••••••••••••SERVICE_TOKEN••••••••••••••••# Workload has not requested its secretsHow it works
Encrypt. Store. Inject.
Encrypt
Secrets are encrypted client-side before reaching the API. AES-256-GCM with per-secret key envelopes. The platform KMS manages the root keys.
Store
Encrypted payloads are persisted with version history. Every mutation is logged in the audit trail. Secrets are scoped to project and environment.
Inject
At workload boot, Nectar resolves declared secret references and injects them as WASI environment variables. No filesystem writes. No network calls from your code.
Features
Secrets done right.
Secret Versions
Every secret update creates a new immutable version. Roll back instantly. Compare versions side by side. Audit who changed what and when.
Environment Scoping
Separate secrets per environment: dev, staging, production. Promote secrets between environments with a single command. No copy-paste.
Automatic Rotation
Define rotation policies. Pollen generates new values, encrypts, and injects them on the next workload boot. Zero downtime rotation.
Fine-grained ACLs
Control who can read, write, and rotate each secret. Scoped to teams, projects, or individual workloads. Integrated with Keystone IAM.