Introduction
What is Basil?
How it works
Backends & custody
Threat model
How it compares
Getting Started
Quickstart
The five-minute demo
Installation
First run: basil init
Make it your own
Running the examples
Migrating from sops-nix to Basil
Issue TLS certificates for your internal services
Configuration
Configuration overview
The catalog (keys)
The policy (authorization)
Backends & capabilities
OpenBao & Vault
AWS KMS
Google Cloud KMS
1Password
Capability policy & reconcile
Unlock & the sealed bundle
Approvals & change control
Limits & resource controls
JWKS HTTP surface
CLI Reference
CLI overview
Command reference
Client Libraries
Client libraries overview
Rust client
Streaming encryption
Go client
Your first integrated service
Other languages
NATS integration
Mint NATS credentials without nsc
Integration patterns
Sealed invocations
NATS bridge
Operations
Crypto: keys & algorithms
Rotating keys
Importing (BYOK) keys & sets
Revocation
Audit logs
Hot reload & admin reload
Health & readiness probes
Policy explain / dry-run
Doctor (preflight checks)
Automated boot unlock
Backup & disaster recovery
Production hardening checklist
Uninstall & removal
Examples
Examples overview
db-keystore backend
Troubleshooting
Error & status code reference
Incident runbook
Reference
Feature matrix
Glossary
RFC compatibility
NATS JWT reference
Stability & upgrades
Security policy
Licenses
CLI Reference
Pages:
CLI overview
Command reference