-
Notifications
You must be signed in to change notification settings - Fork 0
Supported File Formats
camouflage.nvim includes 10 built-in parsers covering 25 file name patterns. Each parser can operate in regex mode or TreeSitter mode (when available) for enhanced detection.
| Format | Extensions | TreeSitter | Nested Keys | Parser |
|---|---|---|---|---|
| Environment |
.env, .env.*, *.env, .envrc, *.sh
|
No | No | env |
| JSON |
*.json, *.jsonc
|
Yes (json) |
Yes | json |
| YAML |
*.yaml, *.yml
|
Yes (yaml) |
Yes | yaml |
| TOML | *.toml |
Yes (toml) |
Yes (sections) | toml |
| Properties |
*.properties, *.ini, *.conf, credentials
|
No | Yes (sections) | properties |
| Netrc |
.netrc, _netrc
|
No | No | netrc |
| XML | *.xml |
Yes (xml) |
Yes | xml |
| HTTP | *.http |
Yes (http) |
Yes (headers, query, JSON body) | http |
| HCL / Terraform |
*.tf, *.tfvars, *.hcl
|
Yes (hcl/terraform) |
Yes | hcl |
| Dockerfile |
Dockerfile, Dockerfile.*, *.dockerfile, Containerfile, Containerfile.*
|
Yes (dockerfile) |
No | dockerfile |
Parses KEY=value and export KEY=value patterns. Supports:
- Simple values:
API_KEY=secret123 - Quoted values:
API_KEY="secret 123"orAPI_KEY='secret 123' - Export syntax:
export API_KEY=secret123 - The other shell declarations, with flags:
readonly API_TOKEN="abc123",declare -x DB_PASSWORD=hunter2,typeset,local - Keys with
.and-in dotenv files (app.secret=,MY-TOKEN=), as dotenv loaders and Docker's--env-fileaccept them.*.shand.envrcare shell scripts and keep shell names - Commented lines (when
parsers.include_commented = true):# API_KEY=old_secret
Configuration:
parsers = {
include_commented = true, -- Include commented-out variables
env = {
include_export = true, -- Include export KEY=value lines
},
}Parses all key-value pairs in JSON files, including deeply nested objects. Uses TreeSitter for accurate detection when available, falls back to vim.json.decode then regex.
- Handles escaped quotes in string values
- Supports nested key paths:
database.connection.password - Masks strings, numbers, and booleans
Configuration:
parsers = {
json = {
max_depth = 10, -- Maximum nesting depth to traverse
},
}Parses YAML files with full nested key support. TreeSitter-enhanced parsing handles complex YAML constructs.
- Nested key paths:
database.connection.password - Multi-line block scalars (
|and>) - Flow pairs:
{key: value} - Anchor/alias handling
Configuration:
parsers = {
yaml = {
max_depth = 10, -- Maximum nesting depth
},
}Parses TOML files with section support.
- Section headers:
[database] - Array sections:
[[servers]] - Nested key paths under sections:
[database]→password = "secret"→database.password
Parses Java-style properties, INI, and conf files.
-
=and:separators:key=valueorkey: value - Section headers:
[section] - Comments:
#and; - Files:
*.properties,*.ini,*.conf,credentials
Parses .netrc / _netrc authentication files.
- Masks values for:
login,password,accountkeywords - Supports multi-line and single-line format:
machine example.com login user@example.com password s3cr3t
Parses XML element content and attributes.
- Element content:
<password>secret</password> - Attributes:
<db password="secret"/> - Nested paths:
database.connection.password - Excludes XML declaration (
<?xml ...?>)
Configuration:
parsers = {
xml = {
max_depth = 10, -- Maximum nesting depth
},
}Parses .http REST client files (used by Kulala.nvim, rest.nvim, VS Code REST Client and similar tools).
- Variable definitions:
@api_key = secret123 - Query parameters with a sensitive name (
api_key,token,signature, ...), asquery.access_token - Headers with a sensitive name (
Authorization,Cookie,X-Api-Key, ...), asheader.Authorization.Authorization: Bearer xkeepsBearervisible, and a cookie header keeps its cookie names - A JSON body value by value (
body.user.password), and the sensitive fields of a form body -
{{variable}}references are left as they are
GET {{base_url}}/users?access_token=abc123
Authorization: Bearer sk-live-abc123xyz789
Content-Type: application/json
{"password": "SuperSecret123!"}Parses HashiCorp Configuration Language files including Terraform.
- Attribute assignments:
password = "secret" - Block definitions:
resource "aws_db_instance" "main" { ... } - Heredoc strings:
<<EOFand<<-EOF - One-line object values:
tags = { token = "x", port = 5432 }, with or without the grammar - Skips variable references (
var.xxx,local.xxx) - Nested block paths
Configuration:
parsers = {
hcl = {
max_depth = 10, -- Maximum block nesting depth
},
}Parses Docker and container build files.
-
ENVinstructions:ENV API_KEY=secret -
ARGinstructions:ARG DB_PASSWORD=default -
LABELinstructions:LABEL version="1.0" - Key=value pairs:
ENV KEY1=val1 KEY2=val2 - Legacy syntax:
ENV KEY value - Files:
Dockerfile,Dockerfile.*,*.dockerfile,Containerfile,Containerfile.*
Each parser that supports TreeSitter follows this strategy:
- If a TreeSitter parser is installed for the language, it's used for more accurate detection
- If it isn't, the parser falls back to its built-in regex patterns
You don't need to install TreeSitter parsers, since the regex fallback works for all formats. TreeSitter gives better detection for complex constructs (nested objects, multi-line values and so on).
Install TreeSitter parsers with:
:TSInstall json yaml toml xml http hcl dockerfileFor file types not covered by built-in parsers, use Custom Patterns for simple config-only Lua patterns or Custom Parsers for reusable runtime parser registration.