Why this exists
One source of truth
Secrets live in 1Password. SSM, dotenv files, Vercel, Render, CapRover, and GitHub Actions all sync from one secrets.manifest.yml, instead of six dashboards edited by hand.
See drift before it bites
diff compares the platforms with 1Password by fingerprint, so raw values never appear. It also flags keys that a platform still has but 1Password has dropped. JSON output is available for dashboards.
A safety net by default
Any push that cannot be proven dev-scoped asks for confirmation first and fails closed in CI. The script that env-sync replaced had no such gate. Every attempt is written to an audit log.
Quickstart
# 1. Is 1Password complete, and can I reach every target?
env-sync validate --service api --env dev
# 2. What has drifted? (fingerprints only, never raw values)
env-sync diff --all --env dev
# 3. Fix it. Risky targets ask first; CI fails closed.
env-sync push --all --env dev --apply
Two implementations, one contract: a TypeScript CLI you can use today, and a Go port that passes the same golden conformance fixtures. The Go port is on the way to a single static binary with no Node dependency.