Skip to content

Supported File Formats

Ahmet Zeybek edited this page Sep 27, 2026 · 4 revisions

Supported File Formats

camouflage.nvim includes 10 built-in parsers covering 25 file name patterns. Each parser can operate in regex mode or TreeSitter mode (when available) for enhanced detection.

Format Overview

Format Extensions TreeSitter Nested Keys Parser
Environment .env, .env.*, *.env, .envrc, *.sh No No env
JSON *.json, *.jsonc Yes (json) Yes json
YAML *.yaml, *.yml Yes (yaml) Yes yaml
TOML *.toml Yes (toml) Yes (sections) toml
Properties *.properties, *.ini, *.conf, credentials No Yes (sections) properties
Netrc .netrc, _netrc No No netrc
XML *.xml Yes (xml) Yes xml
HTTP *.http Yes (http) Yes (headers, query, JSON body) http
HCL / Terraform *.tf, *.tfvars, *.hcl Yes (hcl/terraform) Yes hcl
Dockerfile Dockerfile, Dockerfile.*, *.dockerfile, Containerfile, Containerfile.* Yes (dockerfile) No dockerfile

Format Details

Environment Files (.env)

Parses KEY=value and export KEY=value patterns. Supports:

  • Simple values: API_KEY=secret123
  • Quoted values: API_KEY="secret 123" or API_KEY='secret 123'
  • Export syntax: export API_KEY=secret123
  • The other shell declarations, with flags: readonly API_TOKEN="abc123", declare -x DB_PASSWORD=hunter2, typeset, local
  • Keys with . and - in dotenv files (app.secret=, MY-TOKEN=), as dotenv loaders and Docker's --env-file accept them. *.sh and .envrc are shell scripts and keep shell names
  • Commented lines (when parsers.include_commented = true): # API_KEY=old_secret

Configuration:

parsers = {
  include_commented = true,  -- Include commented-out variables
  env = {
    include_export = true,   -- Include export KEY=value lines
  },
}

JSON

Parses all key-value pairs in JSON files, including deeply nested objects. Uses TreeSitter for accurate detection when available, falls back to vim.json.decode then regex.

  • Handles escaped quotes in string values
  • Supports nested key paths: database.connection.password
  • Masks strings, numbers, and booleans

Configuration:

parsers = {
  json = {
    max_depth = 10,  -- Maximum nesting depth to traverse
  },
}

YAML

Parses YAML files with full nested key support. TreeSitter-enhanced parsing handles complex YAML constructs.

  • Nested key paths: database.connection.password
  • Multi-line block scalars (| and >)
  • Flow pairs: {key: value}
  • Anchor/alias handling

Configuration:

parsers = {
  yaml = {
    max_depth = 10,  -- Maximum nesting depth
  },
}

TOML

Parses TOML files with section support.

  • Section headers: [database]
  • Array sections: [[servers]]
  • Nested key paths under sections: [database] → password = "secret" → database.password

Properties / INI / Conf

Parses Java-style properties, INI, and conf files.

  • = and : separators: key=value or key: value
  • Section headers: [section]
  • Comments: # and ;
  • Files: *.properties, *.ini, *.conf, credentials

Netrc

Parses .netrc / _netrc authentication files.

  • Masks values for: login, password, account keywords
  • Supports multi-line and single-line format:
    machine example.com
    login user@example.com
    password s3cr3t
    

XML

Parses XML element content and attributes.

  • Element content: <password>secret</password>
  • Attributes: <db password="secret"/>
  • Nested paths: database.connection.password
  • Excludes XML declaration (<?xml ...?>)

Configuration:

parsers = {
  xml = {
    max_depth = 10,  -- Maximum nesting depth
  },
}

HTTP (REST Client)

Parses .http REST client files (used by Kulala.nvim, rest.nvim, VS Code REST Client and similar tools).

  • Variable definitions: @api_key = secret123
  • Query parameters with a sensitive name (api_key, token, signature, ...), as query.access_token
  • Headers with a sensitive name (Authorization, Cookie, X-Api-Key, ...), as header.Authorization. Authorization: Bearer x keeps Bearer visible, and a cookie header keeps its cookie names
  • A JSON body value by value (body.user.password), and the sensitive fields of a form body
  • {{variable}} references are left as they are
GET {{base_url}}/users?access_token=abc123
Authorization: Bearer sk-live-abc123xyz789
Content-Type: application/json

{"password": "SuperSecret123!"}

HCL / Terraform

Parses HashiCorp Configuration Language files including Terraform.

  • Attribute assignments: password = "secret"
  • Block definitions: resource "aws_db_instance" "main" { ... }
  • Heredoc strings: <<EOF and <<-EOF
  • One-line object values: tags = { token = "x", port = 5432 }, with or without the grammar
  • Skips variable references (var.xxx, local.xxx)
  • Nested block paths

Configuration:

parsers = {
  hcl = {
    max_depth = 10,  -- Maximum block nesting depth
  },
}

Dockerfile

Parses Docker and container build files.

  • ENV instructions: ENV API_KEY=secret
  • ARG instructions: ARG DB_PASSWORD=default
  • LABEL instructions: LABEL version="1.0"
  • Key=value pairs: ENV KEY1=val1 KEY2=val2
  • Legacy syntax: ENV KEY value
  • Files: Dockerfile, Dockerfile.*, *.dockerfile, Containerfile, Containerfile.*

TreeSitter vs Regex Parsing

Each parser that supports TreeSitter follows this strategy:

  1. If a TreeSitter parser is installed for the language, it's used for more accurate detection
  2. If it isn't, the parser falls back to its built-in regex patterns

You don't need to install TreeSitter parsers, since the regex fallback works for all formats. TreeSitter gives better detection for complex constructs (nested objects, multi-line values and so on).

Install TreeSitter parsers with:

:TSInstall json yaml toml xml http hcl dockerfile

Unsupported Formats

For file types not covered by built-in parsers, use Custom Patterns for simple config-only Lua patterns or Custom Parsers for reusable runtime parser registration.

Clone this wiki locally