← Back to all sparks
I

Infisical

INFRA · APIS
Velocity5.0

Open-source secret management platform for developers

Infisical is outgrowing 'secrets manager' — PAM, PKI sync and credential rotation now dominate its releases

secrets-managementpampkicredential-rotationmachine-identity
Current state
Infisical ships a patch release every few days. The recent stream is dominated by three tracks: privileged access management getting connection tests, CLI domain flags and org-admin auto-enrolment; PKI sync destinations expanding to KEMP load balancers, Nutanix Prism Central and Windows and Linux servers; and credential rotation adding Azure app connections, LDAP and Datadog API keys. Machine identity work runs alongside, including expiry alerting.
Where it's heading
The product is assembling the pieces of a full secrets-and-access platform rather than deepening secret storage. PAM, certificate lifecycle and automated rotation are three separate enterprise categories, and Infisical is now shipping into all of them at once from a single release train. Note that the broader architectural work — secrets brokering through proxied services and an agent-proxy CA — sits just outside this window and is not classified here.
Prediction
Expect PAM to keep absorbing release surface and reach general availability signals, with the proxied-service template library growing beyond the Google Workspace entry point.

Recent moves

  1. 1d ago

    v0.162.16

    Adds expiry alerting for machine identity authentication and a revamped certificate manager UI. Expiry alerts matter in a product where a silently lapsed machine identity breaks automated workloads rather than prompting a human.

    View source ↗
  2. 7d ago

    v0.162.15

    Mostly documentation and CI work — org structure and governance model docs, a FIPS test image build fix — with a machine identity template visibility tweak. Housekeeping between feature releases.

    View source ↗
  3. 9d ago

    v0.162.14

    Adds a Google Workspace service template for proxied services and a last-used timestamp for the agent proxy. The template library is how the brokering architecture becomes usable without hand-configuration.

    View source ↗
  4. 13d ago

    v0.162.13

    Two rotation additions in one release — Azure app connection credentials rotating automatically, and LDAP credential rotation — alongside GCP replication region controls. Rotation is steadily becoming the default expectation rather than a premium add-on.

    View source ↗
  5. 14d ago

    v0.162.12

    Adds PKI sync for KEMP load balancers, a PAM connection test, and session policies on temporary dynamic-secret credentials. The session policy work is the most consequential — it bounds what a short-lived credential can actually do.

    View source ↗
  6. 15d ago

    v0.162.11

    Datadog API key rotation joins the rotation catalogue, and GCP dynamic secrets gain validation that the service account email belongs to the same org — a tenancy boundary that was previously assumed rather than enforced.

    View source ↗