# segmentio/chamber: an SSM Parameter Store secret manager for AWS teams

> Chamber is a Go CLI that stores secrets in AWS SSM Parameter Store and injects them into processes. It fits teams already running on AWS with KMS and per-service IAM, and it is the wrong tool if you want secrets to live outside AWS.

**segmentio/chamber** — CLI for managing secrets

- Repository: https://github.com/segmentio/chamber
- Stars: 2,615 · Forks: 186
- Language: Go
- License: MIT
- Published: 2026-09-28 · Updated: 2026-09-28 · Language: en
- Canonical page: https://hysenlabs.com/projects/segmentio-chamber

## What chamber solves, and who it is actually for

Chamber stores secrets in AWS SSM Parameter Store, which the README describes as "an AWS service for storing secrets". The CLI wraps that store so a developer or a deploy job can write, read, list and export secrets without hand-assembling SSM API calls. The intended user is an engineer or platform team already inside AWS: chamber requires an authenticated AWS user with permission to read and write values in Parameter Store. There is no hosted control plane, no web UI, and no secret server of its own. The README points at an AWS blog post titled The Right Way To Manage Secrets for the longer argument, and it recommends aws-vault as one convenient way to obtain credentials, with the example alias chamberprod='aws-vault exec production -- chamber'. That framing is the honest one: chamber is a thin, opinionated client over a service you already pay for and already govern through IAM. If your organization has not standardized on AWS, the tool has nothing to attach to.

## How chamber maps services and keys onto SSM paths

Since version 2.0 chamber uses Parameter Store's path-based API by default, and version 3.0 made that mandatory. The v3.0 notes state that support added in v2.0 to avoid the path API has been removed and that the CHAMBER_NO_PATHS environment variable "no longer has any effect". The practical consequence is that a service name and a key become a hierarchy in Parameter Store rather than a flat name, which is why the project calls the paths API the recommended best practice by AWS and cites performance benefits. Key normalization happens on write: the README says the dash becomes underscore and letters are upper-cased, so secret_key and secret-key both land as SECRET_KEY. That normalization is convenient but it also means two keys you thought were distinct can collide. Version 3.0 additionally reserves the service name _chamber for chamber's internal use, and the README says you will be warned when using it for any chamber operation. Encryption is delegated to KMS: chamber expects a key with alias parameter_store_key in the account you read and write, and CHAMBER_KMS_KEY_ALIAS overrides it, with CHAMBER_KMS_KEY_ALIAS=aws/ssm given as an example that uses the account's default SSM alias.

## Installing chamber from source and writing a first secret

The README gives one install path directly: a working Go environment. The command installs the v3 module. The README warns that this route produces a binary with no versioning information, so chamber version prints chamber dev rather than a release tag, because version data is injected at compile time by the Makefile. The wiki is cited for Docker images, Linux packages and precompiled binaries, so treat go install as the minimal path rather than the only one.

```bash
go install github.com/segmentio/chamber/v3@latest
```

Before any command works you need AWS credentials in the environment. The README's example wraps chamber in aws-vault. Substitute whatever your organization uses, as long as the resulting environment carries credentials with SSM read and write permission.

```bash
aws-vault exec prod -- chamber
```

Writing a secret takes a service name, a key and a value. Passing - as the value reads from standard input, which keeps the secret out of your shell history. Writing an existing key increments its version rather than overwriting silently.

```bash
chamber write <service> <key> <value|->
```

You can attach tags at write time, but the README notes tagging on write is only available for new secrets. Tags are managed afterwards with the tag subcommands.

```bash
chamber tag write <service> <key> tag1=value1 tag2=value2
chamber tag read <service> <key>
```

Listing shows the key, its version, a last-modified timestamp and the user who wrote it. That version column is the main audit surface chamber gives you without extra tooling.

## Where chamber gets in your way

The KMS key alias is a hard expectation, not a suggestion. Chamber expects to find a key with alias parameter_store_key in the account you are writing to or reading from. If that alias is absent, the setup is incomplete before you type a single command, and the README's Terraform snippet exists precisely because this is a prerequisite people miss. The second constraint is migration debt. Anyone on a pre-2.0 layout that did not use paths must convert, and the v3.0 notes are explicit that CHAMBER_NO_PATHS no longer has any effect. The documented conversion runs through a 2.x binary, not the current one: CHAMBER_NO_PATHS=1 chamber export foo | chamber import foo -. If you upgrade before migrating, you have removed your own escape hatch. Third, throttling. The --min-throttle-delay option no longer has any effect because the underlying AWS SDK dropped support for it with no direct replacement. The substitute is --retry-mode adaptive, which the notes call an experimental model that accounts for throttling errors. That is a real regression in control for anyone who tuned delays deliberately. Finally, the tag replacement flag is flagged as unstable: the README says the option may change before the next major release. Building automation on --delete-other-tags is a bet on an API the maintainers have not frozen.

## Chamber versus reading SSM directly or using Secrets Manager

The obvious alternative is the AWS CLI against SSM Parameter Store, and the difference is not capability but ergonomics and safety. Chamber adds key normalization, version-aware writes, a list view showing version, last-modified time and author, and an export/import pair designed for bulk movement between formats. A raw aws ssm put-parameter call gives you none of that and leaves the naming convention to you. The second alternative is AWS Secrets Manager, which chamber's own dependency list includes as a separate SDK module, and which appears in the codebase as a distinct store implementation. The approaches differ in cost model and rotation story: Secrets Manager is a dedicated secret service with its own rotation features, while chamber's stated design is to keep secrets in Parameter Store, which the README frames as the right way. If you need built-in rotation, chamber is not the layer that provides it. If you simply want secrets addressable by path with IAM as the only access control, Parameter Store plus chamber is the smaller system.

## Maintenance, releases and the MIT licence

The repository is not archived and the last push was on 2026-07-14. Recent releases are v3.1.3 on 2025-07-23, v3.1.4 on 2025-11-18 and v3.1.5 on 2026-02-06. The v3.1.4 release is titled "Updating to 1.25 Go Version", and the module file declares go 1.23.0, so the toolchain requirement moves with Go releases. The v2.13.0 notes state that chamber only tests against Go versions covered by the Go Release Policy, meaning the two most recent major versions, and that release binaries are built with the latest stable Go. That is a deliberate policy, and it means an old Go toolchain in your build image will eventually stop matching what the project supports. Upgrade cost concentrates in major versions: v2.0 changed the default storage format, v3.0 removed the non-path escape hatch and changed the Store interface to require context arguments. The README notes that the context change has no effect for CLI users but requires code updates for anyone using chamber as a library, and that the deprecated NewS3Store constructor was removed in favour of NewS3StoreWithBucket. The licence is MIT, which permits reuse and modification with the usual attribution and warranty terms; the LICENSE file in the repository is the authoritative text, and nothing here is legal advice.

## Conclusion

Adopt chamber if your secrets already live in AWS, your workloads run under IAM roles, and you want a CLI rather than a hosted service. Do not adopt it if you need a non-AWS backend or a UI for non-engineers. Before rolling it out, verify that a KMS key with the alias parameter_store_key exists in each account, that your IAM policy grants the SSM path operations chamber uses, and that no existing secrets are stored in the pre-2.0 non-path format, since v3.0 removed CHAMBER_NO_PATHS and requires migration with a 2.x binary.

## FAQ

### How do I install segmentio/chamber?

The README's direct route is go install github.com/segmentio/chamber/v3@latest with a working Go environment. It notes that this produces a binary without versioning information, so chamber version prints chamber dev. The wiki is linked for Docker images, Linux packages and precompiled binaries.

### What AWS setup does segmentio/chamber require before it works?

You need an authenticated AWS user with permission to read and write values in SSM Parameter Store. Chamber also expects a KMS key with the alias parameter_store_key in the account you read and write, unless you override it with CHAMBER_KMS_KEY_ALIAS.

### How do I write a secret with segmentio/chamber?

Run chamber write <service> <key> <value|->. If you pass - as the value, chamber reads it from standard input. Writing a key that already exists increments its version and stores the new value.

### Does segmentio/chamber still support CHAMBER_NO_PATHS?

No. The v3.0 breaking changes state that support for avoiding the path-based API has been removed and that CHAMBER_NO_PATHS no longer has any effect. The documented migration uses a 2.x version of chamber with export and import.

## Sources

- [Issues](https://github.com/segmentio/chamber/issues)
- [License: MIT](https://github.com/segmentio/chamber/blob/master/LICENSE)
- [README](https://github.com/segmentio/chamber/blob/master/README.md)
- [Releases](https://github.com/segmentio/chamber/releases)
- [segmentio/chamber on GitHub](https://github.com/segmentio/chamber)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/segmentio-chamber
