Skip to main content

env-sync

Push 1Password secrets to six platforms from one manifest, with a confirmation gate before any risky write.

Why this exists

One source of truth

Secrets live in 1Password. SSM, dotenv files, Vercel, Render, CapRover, and GitHub Actions all sync from one secrets.manifest.yml, instead of six dashboards edited by hand.

See drift before it bites

diff compares the platforms with 1Password by fingerprint, so raw values never appear. It also flags keys that a platform still has but 1Password has dropped. JSON output is available for dashboards.

A safety net by default

Any push that cannot be proven dev-scoped asks for confirmation first and fails closed in CI. The script that env-sync replaced had no such gate. Every attempt is written to an audit log.

Quickstart

# 1. Is 1Password complete, and can I reach every target?
env-sync validate --service api --env dev

# 2. What has drifted? (fingerprints only, never raw values)
env-sync diff --all --env dev

# 3. Fix it. Risky targets ask first; CI fails closed.
env-sync push --all --env dev --apply

Two implementations, one contract: a TypeScript CLI you can use today, and a Go port that passes the same golden conformance fixtures. The Go port is on the way to a single static binary with no Node dependency.