OpenStack Barbican

No phone app

6.6No. 15 of 32
in Secrets Management Tools
  • Recognised40% of the score38
  • Phone app26% of the score0
  • Documented20% of the score77
  • Free plan14% of the score100
Free plan
Yes
Runs on
api, Linux, self-hosted

Summary

OpenStack Barbican is ranked #15 of 32 in secrets management tools on Samsung Mobile US Press. It runs on API, Linux, Self-hosted. There is a free plan.

OpenStack Barbican plans and pricing

All plans
Open source Barbican Free No plan limits stated docs.openstack.org · 4 Oct 2026

Compared on secrets management tools

Deployment model
self_hosteddocs.openstack.org

Facts

Purpose
Barbican is the OpenStack Key Manager service for secure storage, provisioning, and management of secrets such as keys, certificates, passwords, and raw binary data.docs.openstack.org · 4 Oct 2026
API
The barbican-api service provides an OpenStack-native REST API for provisioning and managing secrets.docs.openstack.org · 4 Oct 2026
Components
The service includes barbican-api, barbican-worker, and barbican-keystone-listener components.docs.openstack.org · 4 Oct 2026
Secret stores
A plugin architecture lets operators store secrets in software-based stores or hardware devices such as HSMs.docs.openstack.org · 4 Oct 2026
HSM support
The PKCS#11 crypto plugin interfaces with a Hardware Security Module, with master encryption and HMAC keys residing in the HSM.docs.openstack.org · 4 Oct 2026
Integrations
Documented secret-store plugins include KMIP, Dogtag, and Vault, alongside PKCS#11 crypto plugins.docs.openstack.org · 4 Oct 2026
Keystone
The Keystone listener manages Barbican database representations of Keystone projects when those projects are deleted.docs.openstack.org · 4 Oct 2026
Security tradeoff
The default Simple Crypto plugin stores its single encryption key in plaintext in barbican.conf, so access to service nodes must be restricted carefully.docs.openstack.org · 4 Oct 2026
ACL limitation
Container ACL settings are not propagated to associated secrets, and ACL functionality applies only when Barbican is integrated with Keystone.docs.openstack.org · 4 Oct 2026
Customization
Operators can develop custom plugins for secret storage, generation, and event handling; plugin support status can be stable, experimental, or out-of-tree.docs.openstack.org · 4 Oct 2026
Deployment requirement
The installation documentation assumes a working OpenStack deployment.docs.openstack.org · 4 Oct 2026
License
The OpenStack project is provided under the Apache 2.0 license.docs.openstack.org · 4 Oct 2026

Best OpenStack Barbican alternatives

See all 12