secrets/CLAUDE.md
Brian Majewski 585367b9a6 Add support for package.json workspaces in secrets CLI
- Introduced `--workspaces` flag for `push` and `pull` commands to handle environment files in monorepos.
- Updated README and CLAUDE.md to reflect new workspace functionality and installation instructions.
- Enhanced test suite with cases for workspace operations, ensuring proper encryption and decryption of environment files.
- Improved error handling for missing package.json and workspaces field.
- Increased test coverage from 20 to 25 tests.
2026-03-23 17:01:22 -07:00

1.4 KiB

secrets

Encrypted env file sync between machines using age key-file encryption + a private git repo.

Quick Start

brew install age
./secrets init                    # Create ~/.secrets repo + generate age key
cd ~/my-project && ./secrets push # Encrypt .env* files, commit, push
# On other machine:
cd ~/my-project && ./secrets pull # Pull + decrypt .env* files

Testing

brew install bats-core
bats test/secrets.bats

Architecture

Single bash script (secrets) with subcommands: init, push, pull, list, rm, rekey.

  • Encryption: age with key files (not passphrases — age passphrases are non-scriptable)
  • Storage: Private git repo at ~/.secrets/
  • Convention: Globs .env and .env.* (not .envrc, .environment-*)
  • Workspaces: --workspaces flag reads package.json workspaces, requires jq
  • Safety: Pre-commit hook rejects plaintext .env files

Project Structure

secrets              # CLI script (~300 lines bash)
hooks/pre-commit     # Pre-commit hook template
test/
  secrets.bats       # bats-core test suite (25 tests)
  test_helper.bash   # Shared setup/teardown
README.md            # User-facing documentation
CLAUDE.md            # This file

Key file

~/.secrets/key.txt is the age identity (private key). It is gitignored and must be copied manually to each machine once.

Environment variable

SECRETS_DIR overrides the default ~/.secrets location (useful for testing).