- Introduced `--workspaces` flag for `push` and `pull` commands to handle environment files in monorepos. - Updated README and CLAUDE.md to reflect new workspace functionality and installation instructions. - Enhanced test suite with cases for workspace operations, ensuring proper encryption and decryption of environment files. - Improved error handling for missing package.json and workspaces field. - Increased test coverage from 20 to 25 tests.
1.4 KiB
1.4 KiB
secrets
Encrypted env file sync between machines using age key-file encryption + a private git repo.
Quick Start
brew install age
./secrets init # Create ~/.secrets repo + generate age key
cd ~/my-project && ./secrets push # Encrypt .env* files, commit, push
# On other machine:
cd ~/my-project && ./secrets pull # Pull + decrypt .env* files
Testing
brew install bats-core
bats test/secrets.bats
Architecture
Single bash script (secrets) with subcommands: init, push, pull, list, rm, rekey.
- Encryption:
agewith key files (not passphrases — age passphrases are non-scriptable) - Storage: Private git repo at
~/.secrets/ - Convention: Globs
.envand.env.*(not.envrc,.environment-*) - Workspaces:
--workspacesflag readspackage.jsonworkspaces, requiresjq - Safety: Pre-commit hook rejects plaintext
.envfiles
Project Structure
secrets # CLI script (~300 lines bash)
hooks/pre-commit # Pre-commit hook template
test/
secrets.bats # bats-core test suite (25 tests)
test_helper.bash # Shared setup/teardown
README.md # User-facing documentation
CLAUDE.md # This file
Key file
~/.secrets/key.txt is the age identity (private key). It is gitignored and must be copied manually to each machine once.
Environment variable
SECRETS_DIR overrides the default ~/.secrets location (useful for testing).