Project reference ↗

Goldfish was a browser-based interface and workflow tool for HashiCorp Vault, the service used to control access to secrets. It helped operators inspect access policies and perform administration tasks without working only through command-line or API calls. That was useful when teams needed a shared interface around Vault's controls. The project is archived, and Vault's own interface should not be assumed to reproduce every custom Goldfish workflow.

Deployment and operating notes

The archived incubator chart identifies Caiyeon/goldfish, not another same-name project. The Goldfish repository itself was archived by its owner on October 6, 2019. Its documentation describes a Vault UI and policy workflows with AppRole bootstrapping. HashiCorp Vault now documents its own built-in UI, but that is not proof that every Goldfish approval, token-search or policy workflow has a direct equivalent.

For an existing installation, inventory the Vault version, secret-engine versions, authentication methods, AppRole permissions and custom workflows. Review whether the UI can obtain highly privileged tokens or expose secret values in browser or server logs. Test a low-privilege user, denied path, token expiry and the specific policy-change workflow against a non-production Vault instance. If replacing Goldfish with the built-in UI or another client, map capabilities explicitly and remove the old AppRole only after users have a working path. Preserve Vault’s own backups and recovery keys independently of UI configuration. No supported current Goldfish/Vault matrix or automatic workflow migration was established, so this entry remains unverified for new adoption.

Historical upstream link check · 2026-10-09

The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub marks Caiyeon/goldfish as archived. This confirms the repository's read-only archive state; any successor or supported distribution needs separate evidence. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Preserved for context. Commands, versions, prices and results below reflect the original research.

This Helm chart simplifies the deployment of goldfish on Kubernetes. Goldfish – A HashiCorp Vault UI and workflow tool.

Goldfish answers many auditing and administration questions that Vault API can’t:

  • Right now, are there any root tokens in Vault?
  • Which policies, users, and tokens can access this particular secret path?
  • The unseal admins are working from home, but we need a policy changed.
  • How do we generate a root token only for this change, and make sure it’s revoked after?
  • I store my policies on a Github repo. Can I deploy all my policies in one go? See more
  • If I remove this secret/policy, will anybody’s workflow break?

 

Deployment

Steps:

  1. Write goldfish approle (only needs to be done once)
  2. Deploy goldfish binary
  3. Bootstrap goldfish with an approle secret id

 

Features

  • Hot-loadable server settings from a provided vault endpoint
  • Displaying a vault endpoint as a ‘bulletin board’ in the homepage
  • Logging in with token, userpass, Github, or LDAP
  • Secret Reading/editing/creating/listing
  • Auth Searching/creating/listing/deleting
  • Mounts Listing
  • Policies Searching/Listing
  • Encrypting and decrypting arbitrary strings using transit backend

Sources & further reading

  1. Goldfish upstream identity
  2. Vault built-in UI configuration
  3. Historical Goldfish chart identity
  4. Recovered historical source (Common Crawl index)

Spotted something that needs another look?

Help improve this page →