envsecrets v1.0.0 - Initial Release
A lightweight CLI tool for securely managing environment variables and secrets with encryption.
Features
Core Commands:
init- Initialize encrypted vaults for different environmentsadd- Add or update secrets with AES-256-GCM encryptionget- Retrieve individual secretsdelete- Remove secrets from vaultsexport- Export all secrets to dotenv or JSON formatimport- Import secrets from dotenv or JSON filesrotate- Change vault passphrase with automatic re-encryptionclear- Clear cached passphrases from system keyringdestroy- Permanently delete vaults
Security Features:
- AES-256-GCM authenticated encryption
- Argon2id key derivation (memory-hard, GPU-resistant)
- System keyring integration for passphrase caching
- Secure file permissions (0o600)
Key Benefits:
- Version control your encrypted secrets safely
- Track secret changes through git history
- Collaborate securely with your team
- No separate secret management infrastructure needed
Installation
go install github.com/suvaidkhan/envsecrets@v1.0.0
Quick Start
# Initialize a vault
envsecrets init --env production
# Add secrets
envsecrets add --env production --key API_KEY --value "your-secret"
# Export to .env file
envsecrets export --env production > .env