Anbu is a self-hosted IT hub: an encrypted secrets vault, a task list, a web SSH terminal, AWS access, and EC2 workstation management behind one web UI and one REST API.
It runs as a single binary for one person or a small team behind a forward-auth proxy. It has no login of its own and is not a multi-tenant password manager.
| Area | What it does |
|---|---|
| Vault | Typed secrets (login, SSH key, AWS static keys, AWS SSO, GitHub PAT, generic, file) with TOTP codes, custom fields, Ed25519 key generation, and plaintext export and import |
| Tasks | Single-line tasks with priority, due date, and overdue tracking |
| SSH | Stored hosts and EC2 machines in a browser terminal, with trust-on-first-use host keys |
| AWS | Static keys, ad-hoc keys, and SSO profiles through the device flow, plus an aws CLI runner |
| Machines | EC2 workstations on a per-account scaffold, with create, start, stop, resize, remove, live pricing, and a bootstrap probe |
| Tools | Hashes, YAML and JSON conversion, time parsing, UUIDs, passphrases, random strings, JWT, Base64, URL, case, and text stats |
mkdir -p $HOME/.anbu && sudo chown 10001:10001 $HOME/.anbudocker run -d --name anbu \
-p 127.0.0.1:8080:8080 \
-v $HOME/.anbu:/data \
tanq16/anbu:latestAvailable at http://localhost:8080, and only on the host's loopback interface, since anbu has no login of its own. The same setup as a compose file:
services:
anbu:
image: tanq16/anbu:latest
container_name: anbu
restart: unless-stopped
ports:
- "127.0.0.1:8080:8080"
volumes:
- ./data:/data # change as neededThe container runs as UID and GID 10001, so the mounted directory must be writable by that user. The image includes the AWS CLI v2 for the command runner.
Download a binary from releases for Linux or macOS on AMD64 or ARM64, then run anbu serve. The command runner needs the aws CLI on the server's PATH.
Requires Go 1.27 or newer, curl, and uv (for the Nerd Font asset).
git clone https://github.com/tanq16/anbu.git && cd anbu && make buildanbu serve # http://0.0.0.0:8080, data in ~/.config/anbu/data
anbu serve -p 9000 -d /srv/anbu-d names the data directory. It is created at 0700, and every file in it is 0600.
| Path | Holds |
|---|---|
password |
the vault password in plaintext, generated on first start |
vault.json |
every secret and scaffold key, AES-256-GCM encrypted under a PBKDF2 key from the password |
tasks.json, settings.json, hosts.json |
tasks, settings, and stored SSH hosts in plaintext |
known_hosts |
host keys for every SSH target |
aws/ |
empty AWS config files and the HOME of the aws CLI |
Back up the whole directory. The vault cannot be read without the password file next to it. Rotate the password under Settings in the UI.
Anbu has no users, sessions, or tokens. Put it behind a forward-auth proxy that also passes WebSocket upgrades through for /ws/terminal. The proxy must forward the original Host header, because the terminal and the API reject a request whose Origin does not match it. The UI needs HTTPS or localhost for its copy buttons to work.
The api command group calls the REST API and prints the raw JSON response.
anbu api setup https://anbu.example.com -H "X-Proxy-Token: <token>"
anbu api secrets list
anbu api secrets get github
anbu api secrets totp google-work
anbu api secrets file kubeconfig > ~/.kube/config
anbu api ssh targets
anbu api machines list corp:adminsetupwrites~/.config/anbu/api.json, and its headers ride on every call so the proxy admits the CLI.- Without
api.json, calls go tohttp://localhost:8080.ANBU_URLoverrides the URL for one invocation. secrets fileprints the content of a file secret byte for byte, so it can be redirected to a file.- An HTTP error or a connection failure is logged and exits 1.
An SSO profile is referenced as <secret>:<profile>. Once the SSO session is logged in through the UI, anbu api secrets get prints temporary credentials in the credential_process format:
[profile corp-admin]
credential_process = anbu api secrets get corp:admin
region = us-west-2- SSO sessions live in memory only. A restart needs a new device login, and an expired session returns
401withsso login required. - EC2 jobs run one at a time in a queue held in memory. A restart drops queued jobs and job history.
- Scaffold keys: each account and region gets its own SSH key, stored encrypted in
vault.jsonbeside the secrets. Keys are not listed in the Vault, are included in vault export, and are deleted by scaffold teardown. - Adopting a sharingan scaffold: paste
~/.config/sharingan/id_ed25519into the scaffold view. Its existing machines stay reachable. - Pricing for machine options and the machine list is cached per account and region for an hour, so the first request in an hour is slow.
- Host key changes fail the connection. Clear the old key with Forget host key in the SSH view.







