authentik
The first patch on 2026.8 is twenty-odd fixes and no new surface.
A side-by-side editorial comparison of Buildkite and Doppler — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | Buildkite | Doppler |
|---|---|---|
| Sector | Infra & APIs | Infra & APIs |
| Velocity score | 6.3 | 0.0 |
| Sparks · 30d | 0 | 0 |
| Top themes | ci-cd, github-actions-compat, hosted-agents, credential-scoping | secrets-management, on-prem, secret-rotation, terraform |
| Last editorial update | 1d ago | 4d ago |
| Website | — | Visit → |
Buildkite is prying CI loose from the git forge while shrinking what an agent is trusted with.
Three threads run through the window. Buildkite keeps decoupling CI from the git forge: GitHub Actions workflows run unchanged in a public-preview plugin that now handles reusable workflows, Docker-based actions and service containers, and Buildkite shipped as a Cursor Origin launch partner alongside GitHub, GitLab and Bitbucket. Credentials are getting narrower — stack-managed ephemeral agents now register with a fifteen-minute job acquisition token scoped to one named job instead of the cluster agent token. And hosted-agent access keeps widening: after desktop and terminal access for macOS, the CLI's bk job ssh now reaches running Linux hosted jobs.
Doppler shipped an on-prem build — the secrets manager that only ran as SaaS now runs in your datacenter.
Monthly digests, each one a list, and the captured bodies cut off partway so only the opening items are legible. June leads with Doppler On-prem, alongside role filters on the dashboard, warnings that show downstream impact before deleting inherited or referenced data, and fuzzy matching in secret search. The months before it are steady platform work: Integration Access Scoping via API and Terraform, the ability to redact every historical version of a secret so deleted history is genuinely gone, Azure Service Principal rotated and dynamic secrets, activity-log forwarding to multiple destinations per service type including AWS SQS, and CLI token creation from the MCP server.
Three threads run through the window. Buildkite keeps decoupling CI from the git forge: GitHub Actions workflows run unchanged in a public-preview plugin that now handles reusable workflows, Docker-based actions and service containers, and Buildkite shipped as a Cursor Origin launch partner alongside GitHub, GitLab and Bitbucket. Credentials are getting narrower — stack-managed ephemeral agents now register with a fifteen-minute job acquisition token scoped to one named job instead of the cluster agent token. And hosted-agent access keeps widening: after desktop and terminal access for macOS, the CLI's bk job ssh now reaches running Linux hosted jobs.
The positioning is stated outright in the Origin post — your CI platform should not depend on your git forge — and the GitHub Actions compatibility work aims the same argument at the incumbent, letting teams run existing workflows before committing to a rewrite. Underneath, Buildkite is rebuilding hosted agents into something you can reach into interactively: terminal, then desktop, now SSH on Linux, all through one CLI. The credential work runs the other direction, moving from long-lived cluster tokens toward per-job issuance, with the Kubernetes stack already defaulting to it.
Custom stack implementations are the likely next surface to adopt job acquisition tokens, since the Stacks API already exposes issuance and the Kubernetes stack defaults to it. Expect the remaining hosted-agent access gaps to close the same way — Linux desktop access is the obvious symmetry left after SSH.
Monthly digests, each one a list, and the captured bodies cut off partway so only the opening items are legible. June leads with Doppler On-prem, alongside role filters on the dashboard, warnings that show downstream impact before deleting inherited or referenced data, and fuzzy matching in secret search. The months before it are steady platform work: Integration Access Scoping via API and Terraform, the ability to redact every historical version of a secret so deleted history is genuinely gone, Azure Service Principal rotated and dynamic secrets, activity-log forwarding to multiple destinations per service type including AWS SQS, and CLI token creation from the MCP server.
Two commitments run through this window. The first is that everything must be reachable programmatically — API and Terraform coverage for access scoping, Change Requests endpoints in the v3 API, service account identity management, MCP-driven CLI authentication. The second is control over the secret's whole lifecycle rather than its current value: rotation, dynamic generation, history redaction, and delete-time impact warnings all treat a secret as something with a past and dependents. On-prem is what those two make sellable to the customers who could not use Doppler at all.
Expect the on-prem build to drive the next stretch of work — parity gaps, upgrade paths, and air-gapped handling of the integrations that currently assume outbound access. The truncated digests make anything finer than that unreadable from the feed.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Buildkite or Doppler.
The first patch on 2026.8 is twenty-odd fixes and no new surface.
Alert rate limits stop being per-source and start being per-tenant, by query.
The essay series keeps running ahead of the products it describes.
Both lines patch on the same day, and the reverted JSONata upgrade finally sticks.
The 3.x line finally ships function: authenticated secret writes and render patches.
Folder-level RBAC lands, and approvals finally get a webhook to talk to.
See all Buildkite alternatives → · See all Doppler alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Buildkite is currently shipping more aggressively (velocity 6.3 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Buildkite is currently shipping more aggressively (velocity 6.3 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Buildkite alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Buildkite alternatives" section above for the current picks, or visit /alternatives/buildkite for the full list with editorial commentary on each.
Top Doppler alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Doppler alternatives" section above for the current picks, or visit /alternatives/doppler for the full list with editorial commentary on each.