Mausoleum.App
0.1.0
dotnet tool install --global Mausoleum.App --version 0.1.0
dotnet new tool-manifest
dotnet tool install --local Mausoleum.App --version 0.1.0
#tool dotnet:?package=Mausoleum.App&version=0.1.0
nuke :add-package Mausoleum.App --version 0.1.0
Mausoleum: Secure TUI Vault Manager
💀 Mausoleum is a high-security Terminal User Interface (TUI) designed for power users who prefer the command line over bulky GUIs but refuse to compromise on secret management.
Mausoleum serves as a specialized gateway to Azure Key Vault. It provides a fast, keyboard-centric interface to manage secrets, featuring local master password protection inspired by the KeePass security model.
🛠 Tech Stack
- Language: C# (.NET 8.0+)
- Frontend: Spectre.Console (Rich TUI components)
- Secret Provider: Azure Key Vault (
Azure.Security.KeyVault.Secrets) - Security: Local AES-256 encryption for session state and master password hashing.
🔒 Security Model
Mausoleum acts as a local proxy to your cloud secrets:
- Master Password: Required upon startup to derive a local encryption key.
- Azure Integration: Authenticates via
DefaultAzureCredential. - Obfuscation: All sensitive values are masked in the UI by default.
- Clipboard Safety: Copied values remain in the clipboard for a configurable short duration before being cleared.
🚀 Getting Started
Prerequisites
- .NET 8.0 SDK
- An active Azure Subscription with a Key Vault.
- Azure CLI logged in (
az login).
Installation (as a .NET Tool)
Once published to NuGet, you can install Mausoleum globally:
dotnet tool install --global Mausoleum.App
After installation, run it from anywhere:
mausoleum
Setup & Installation (Local Development)
Clone the repository:
git clone https://github.com/your-repo/mausoleum.git cd mausoleumConfigure Azure Permissions (RBAC): Mausoleum uses Azure Role-Based Access Control (RBAC) to interact with Key Vault. Your authenticated identity needs the
Key Vault Secrets Officerrole to read, create, and update secrets.Run the following Azure CLI command, replacing the placeholders with your actual values:
az role assignment create \ --role "Key Vault Secrets Officer" \ --assignee <YOUR_OBJECT_ID> \ --scope "/subscriptions/<YOUR_SUBSCRIPTION_ID>/resourcegroups/<YOUR_RESOURCE_GROUP>/providers/microsoft.keyvault/vaults/<YOUR_KEY_VAULT_NAME>"Note: Role assignments can take a few minutes to propagate in Azure.
Configure Environment: Set your Vault URI in
Mausoleum.App/appsettings.json:{ "VaultUri": "https://<YOUR_KEY_VAULT_NAME>.vault.azure.net/" }Run the App:
dotnet run --project Mausoleum.App
⌨️ Keybindings
| Keybinding | Action |
|---|---|
↑ / ↓ |
Navigate secret list |
Enter |
View secret details (Obfuscated) |
Ctrl + C |
Copy secret value to clipboard |
Ctrl + N |
Create a new secret |
Delete |
Delete secret (Requires confirmation) |
Ctrl + F |
Filter/Search secrets |
Esc |
Go back / Exit |
Mausoleum: Rest your secrets in peace.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
| Version | Downloads | Last Updated | |
|---|---|---|---|
| 0.1.0 | 160 | 5/3/2026 |