← Back to all sparks
D

Doppler

INFRA · APIS
Velocity0.0

Secrets management platform for syncing environment variables across environments

Doppler shipped an on-prem build — the secrets manager that only ran as SaaS now runs in your datacenter.

secrets-managementon-premsecret-rotationterraformaudit-logging
Current state
Monthly digests, each one a list, and the captured bodies cut off partway so only the opening items are legible. June leads with Doppler On-prem, alongside role filters on the dashboard, warnings that show downstream impact before deleting inherited or referenced data, and fuzzy matching in secret search. The months before it are steady platform work: Integration Access Scoping via API and Terraform, the ability to redact every historical version of a secret so deleted history is genuinely gone, Azure Service Principal rotated and dynamic secrets, activity-log forwarding to multiple destinations per service type including AWS SQS, and CLI token creation from the MCP server.
Where it's heading
Two commitments run through this window. The first is that everything must be reachable programmatically — API and Terraform coverage for access scoping, Change Requests endpoints in the v3 API, service account identity management, MCP-driven CLI authentication. The second is control over the secret's whole lifecycle rather than its current value: rotation, dynamic generation, history redaction, and delete-time impact warnings all treat a secret as something with a past and dependents. On-prem is what those two make sellable to the customers who could not use Doppler at all.
Prediction
Expect the on-prem build to drive the next stretch of work — parity gaps, upgrade paths, and air-gapped handling of the integrations that currently assume outbound access. The truncated digests make anything finer than that unreadable from the feed.

Recent moves

  1. 2mo ago

    Doppler On-prem released

    ⚡ SPARK

    Doppler On-prem is released, with the rest of the month going to dashboard role filters, downstream-impact warnings before deleting inherited or referenced data, and fuzzy secret search. The self-hosted build is the item that changes who can buy the product at all.

    View source ↗
  2. 3mo ago

    Terraform support for access scoping and full secret-history redaction

    Integration Access Scoping becomes reachable through the API and Terraform, and every historical version of a secret can be redacted by name or ID so deleted history is fully scrubbed. History redaction is the substantive one — it answers the question an auditor asks after a leak.

    View source ↗
  3. 4mo ago

    Multiple activity-log forwarding destinations and AWS SQS support

    Activity log forwarding supports multiple destinations per service type — several independent webhook, Slack, Discord, and Teams endpoints — with AWS SQS added as a target. Audit plumbing for organizations where more than one team needs the same stream.

    View source ↗
  4. 5mo ago

    Azure Service Principal rotated and dynamic secrets

    Azure Service Principal secrets can be rotated and generated dynamically through a managing Service Principal, and global search gains a view-all-secrets option. Another cloud provider brought into the rotation model Doppler already runs elsewhere.

    View source ↗
  5. 6mo ago

    CLI token creation from the MCP server, with attribution in logs

    CLI tokens can be created from the MCP server so developers authenticate directly from MCP-powered tools, and activity and config logs now mark actions taken through it. The logging half matters — an assistant acting on secrets is only acceptable if its actions are attributable.

    View source ↗
  6. 7mo ago

    AWS Secrets Manager multi-secret sync loses its 64KiB limit

    The 64KiB config size limit is removed for the AWS Secrets Manager multi-secret sync strategy, with added AWS region support and two small fixes. A ceiling removed for customers whose configs had outgrown it.

    View source ↗