<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type="text/xsl" href="rss.xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>env-sync Blog</title>
        <link>https://env-sync.catesworks.dev/blog</link>
        <description>env-sync Blog</description>
        <lastBuildDate>Mon, 28 Sep 2026 00:00:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <item>
            <title><![CDATA[Porting env-sync, and the safety net it never had]]></title>
            <link>https://env-sync.catesworks.dev/blog/2026/09/28/porting-env-sync</link>
            <guid>https://env-sync.catesworks.dev/blog/2026/09/28/porting-env-sync</guid>
            <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[env-sync started as a set of scripts inside a skills repo. They pushed 1Password secrets to six platforms, and they did it well. They had one gap: nothing stopped a push to production that you did not mean to run.]]></description>
            <content:encoded><![CDATA[<p><code>env-sync</code> started as a set of scripts inside a skills repo. They pushed 1Password secrets to six platforms, and they did it well. They had one gap: nothing stopped a <code>push</code> to production that you did not mean to run.</p>
<!-- -->
<p>The port to a standalone tool kept the original behavior exactly. All 191 original tests carry over as a pinned baseline, and a set of golden fixtures records every adapter's <code>readCurrent</code> and <code>pushValues</code> behavior. Then the port added one thing on purpose: a confirmation gate before any <code>push --apply</code> that cannot be proven safe.</p>
<p>Getting that gate right took three tries. Checking the <code>--env</code> string alone was unsafe, because Vercel, Render, and CapRover ignore <code>--env</code> completely. Checking each target's manifest fields was better, but an adversarial review found that a Vercel target declared as <code>development</code> can still update a live entry scoped to production. The rule that shipped auto-approves only targets whose write scope is derived from <code>--env</code> in code. Everything else asks. The <a class="" href="https://env-sync.catesworks.dev/docs/architecture#the-protection-rule">architecture page</a> has the full story.</p>
<p>The same golden fixtures now also check a second, independent implementation in Go, which is on the way to a single static binary. It passes every fixture. It has not yet run against a real 1Password Service Account, so the TypeScript CLI remains the one to use today.</p>]]></content:encoded>
            <category>Release notes</category>
        </item>
    </channel>
</rss>