Project reference ↗

Monax Hoard stored files as encrypted objects identified by their contents rather than by an ordinary filename. Its documented design derived encryption from the plaintext's hash, so someone who knew the original file or its hash could retrieve it. That supported a particular content-sharing model across storage backends, not ordinary secret-key confidentiality. This entry helps identify and recover that historical object store; the unrelated Hoard memory allocator is a different project.

Deployment and operating notes

This entry concerns Monax Hoard, a deterministically encrypted content-addressed object store, not the unrelated memory allocator. The archived Helm README explicitly deprecates its chart and describes plaintext-hash-derived encryption and several storage backends. The recorded monax/hoard repository returned unavailable during review, so current implementation ownership, security maintenance and packaging remain unresolved.

For a surviving deployment, preserve the exact image, source provenance if available, object metadata, backend configuration and grants needed to retrieve content. The described encryption design permits retrieval by parties that know the plaintext or its hash; do not reinterpret it as ordinary random-key confidentiality. Test export and decryption of representative objects before changing storage or adopting a replacement. Another S3-compatible service will not necessarily understand Hoard addresses or grants, so migration may require reading through the original service and re-encrypting data under a new model. Retain protected recovery copies and verify checksums. No automatic successor or security equivalence was established by this review.

Historical upstream link check · 2026-10-09

The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub confirms that helm/charts is archived: this is a historical chart distribution, not evidence that the application itself is retired. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Original publication: 2019-01-24T07:21:20+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.

Hoard is a stateless, deterministically encrypted, content-addressed object store.

It currently supports local persistent storage, S3 and GCS backends, though IPFS integration is currently under development.

Files that are sent to Hoard are symmetrically encrypted, where the secret is the hash of the plaintext file, and then stored in the configured backend – this enables any party with knowledge of the hash or original file to retrieve it from the store.

Planned storage backends are:

  • BigchainDB (and IPDB)
  • Tendermint

It encrypts deterministically (convergently) because it encrypts an object using the object’s hash (SHA256) as the secret key (which can than be shared as a ‘grant’).

It is content-addressed because encrypted objects are stored at an address determined by the encrypted object’s hash (SHA256 again).

The post Hoard appeared first on kubedex.com.

Sources & further reading

  1. Archived Hoard chart identity and design
  2. Recovered historical source

Spotted something that needs another look?

Help improve this page →