Skip to content

envctl v1.0.0

Choose a tag to compare

@alessbarb alessbarb released this 28 Mar 10:39
· 288 commits to main since this release

First stable release of envctl.

envctl provides a deterministic, local-first approach to managing .env.local files by centralizing them in a user-owned vault and linking them back into repositories using symlinks.

This release establishes a stable foundation for explicit, safe, and consistent environment management across projects.


Highlights

  • Stable command set:

    • init, repair, unlink, status, set, doctor, remove, config init
  • Centralized vault with unique per-project directories (<slug>--<id>)

  • Repository .env.local files managed as symlinks to the vault

  • XDG-based configuration (~/.config/envctl/config.json)

  • Strict safety guarantees (no implicit overwrites or destructive operations)

  • Read-only diagnostics via doctor

  • Comprehensive test suite covering commands and edge cases


What is included in v1.0.0

  • Project registration and identity model based on repository fingerprint
  • Vault structure with deterministic path resolution
  • Symlink-based linking between repository and vault
  • Explicit command behavior with clear failure modes
  • Permission model enforcing user-only access (0700 directories, 0600 files)

Security

  • Secrets are never printed in command output
  • Vault directories and files are restricted to the current user
  • Unsafe configurations are detected via doctor
  • Regular files are never overwritten without explicit confirmation

Important:

  • No encryption at rest (intentional in v1)
  • Assumes a trusted single-user environment

Known limitations

  • No encryption support
  • JSON configuration only
  • No repository listing command
  • No machine-readable output (--json)
  • Limited native Windows support due to symlink constraints

Installation

python3 -m venv .venv
source .venv/bin/activate
pip install -U pip
pip install -e .

Design principles

envctl v1 is intentionally constrained:

  • local-only
  • explicit operations
  • deterministic behavior
  • no hidden state or automation

This version focuses on correctness, safety, and predictability.


Notes

envctl v1.0.0 defines a baseline model for managing local environment files without duplication or implicit behavior.