Something went wrong. Try again.
[READ-ONLY] Mirror of https://github.com/andreijiroh-dev/dotenvx-secretstore. A git-backed experiment with using dotenvx for managing CI/prod secrets.
Something went wrong. Try again.
JavaScript 91%
Shell 6%
3%
Commits 23
stash all the things for now in one commit
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.dev>
chore(secrets): update CI secrets
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.xyz>
tools: work on configuration related chaos
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.xyz>
tools: work on git and config related stuff
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.xyz>
tools: add repo url for provenance
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.xyz>
ci: fix auth chaos and update secrets one more time
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.xyz>
legal: add licenses to tools directory for compliance
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.xyz>
ci: implement provenance signing on npm publish
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.xyz>
ci: add automation for tools cli release and update secrets and gitignore along the way
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.xyz>
tools: prepare v0.1.0 release later this week
Signed-off-by: Andrei Jiroh Halili <ajhalili2006@andreijiroh.xyz>
Tags 1
Latest
README.md
@ajhalili2006/dotenvx-secretstore #
A git-backed experiment with using dotenvx for managing CI/prod secrets. Kinda
similar to using gopass, but without the GPG/SSH key wrangling and web-based
dashboard chaos.
Related projects #
dotenv-tools- CLI tool to manage repositories like tbis one (accessible locally vianpm run cliat project root directory)dotenv-keysshell hook and function- GitHub Actions integration
Rationale #
I am currently a Doppler user for safekeeping secrets, but plan to switch to
dotenvx and use plain git for audit logs. The plan is simple or complex
depending on who asked. In a nutshell:
- Store
.envfiles in a central repository like this for auditing and ease of management - Store the private keys securely in Doppler or straight to CI secrets setting.
- In each CI job, pull project-specifics and load them using
dotenvxcli
Requirements #
dotenvxcli for setup and maintenance (also accessible viadotenv-tools dotenvx)- basically
gitfor everything else andbash+nodejsfor the tools here
Usage #
First Use Setup #
# install dotenvx (optional)
curl -fsSL https://scripts.andreijiroh.xyz/tools/dotenvx | bash -s -- --directory=$HOME/.local/bin
# setup project-specifics
npm run cli -- projects add <project-name> [--copy-ci-secrets|--commit]
# push to project's .env file, optionally
npm run cli -- secrets push --repo-path=/path/to/local-copy [--upload-dotenv-keys=<gh|glab|doppler>|--no-commit] <project-name|meta> [optional-env-file]
Managing secrets #
cd projects/<project-name> # or stay in root directory for meta
# add a secret via dotenvx
dotenvx set [-f .env.ci [--plain] --] NAME somerandomtexthere
# push to repo to sync
./bin/push-secrets --repo-path=/path/to/local-copy [--upload-dotenv-keys=<gh|glab|doppler>|--no-commit] <project-name|meta> [optional-env-file]