<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type="text/xsl" href="atom.xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <id>https://env-sync.catesworks.dev/blog</id>
    <title>env-sync Blog</title>
    <updated>2026-09-28T00:00:00.000Z</updated>
    <generator>https://github.com/jpmonette/feed</generator>
    <link rel="alternate" href="https://env-sync.catesworks.dev/blog"/>
    <subtitle>env-sync Blog</subtitle>
    <icon>https://env-sync.catesworks.dev/img/favicon.ico</icon>
    <entry>
        <title type="html"><![CDATA[Porting env-sync, and the safety net it never had]]></title>
        <id>https://env-sync.catesworks.dev/blog/2026/09/28/porting-env-sync</id>
        <link href="https://env-sync.catesworks.dev/blog/2026/09/28/porting-env-sync"/>
        <updated>2026-09-28T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[env-sync started as a set of scripts inside a skills repo. They pushed 1Password secrets to six platforms, and they did it well. They had one gap: nothing stopped a push to production that you did not mean to run.]]></summary>
        <content type="html"><![CDATA[<p><code>env-sync</code> started as a set of scripts inside a skills repo. They pushed 1Password secrets to six platforms, and they did it well. They had one gap: nothing stopped a <code>push</code> to production that you did not mean to run.</p>
<!-- -->
<p>The port to a standalone tool kept the original behavior exactly. All 191 original tests carry over as a pinned baseline, and a set of golden fixtures records every adapter's <code>readCurrent</code> and <code>pushValues</code> behavior. Then the port added one thing on purpose: a confirmation gate before any <code>push --apply</code> that cannot be proven safe.</p>
<p>Getting that gate right took three tries. Checking the <code>--env</code> string alone was unsafe, because Vercel, Render, and CapRover ignore <code>--env</code> completely. Checking each target's manifest fields was better, but an adversarial review found that a Vercel target declared as <code>development</code> can still update a live entry scoped to production. The rule that shipped auto-approves only targets whose write scope is derived from <code>--env</code> in code. Everything else asks. The <a class="" href="https://env-sync.catesworks.dev/docs/architecture#the-protection-rule">architecture page</a> has the full story.</p>
<p>The same golden fixtures now also check a second, independent implementation in Go, which is on the way to a single static binary. It passes every fixture. It has not yet run against a real 1Password Service Account, so the TypeScript CLI remains the one to use today.</p>]]></content>
        <category label="Release notes" term="Release notes"/>
    </entry>
</feed>