What is env-sync?
env-sync is a command-line tool that keeps secrets in sync between 1Password and the platforms your services actually run on. You describe each service once in a secrets.manifest.yml: where its secrets live in 1Password, and which targets need them. env-sync then diffs, validates, or pushes those values to six target platforms:
- AWS SSM Parameter Store (
ssm) - Local dotenv files (
dotenv) - Vercel project environment variables (
vercel) - Render service environment variables (
render) - CapRover app environment variables (
caprover, read-only by default) - GitHub Actions repository and environment secrets (
github-actions)
1Password stays the single source of truth. env-sync diff shows you where a platform has drifted from it (using fingerprints, never raw values), and env-sync push --apply fixes that drift. Every push that cannot be proven safe asks for confirmation first, and it fails closed in CI. The original script that env-sync was ported from had no such gate.
Where it stands today
env-sync is an internal tool in a private repository. It has no published package or binary release yet. To install it, clone the repository and build it (see Getting Started). A real distribution mechanism, such as an npm package or GitHub Releases binaries, is an open follow-up.
There are two implementations of the same contract:
- TypeScript (
apps/cli+packages/core): the primary implementation today. It is a faithful port of the originalsecrets-source-of-truthscripts, and all 191 of the original tests carry over unchanged. - Go (
go/): an independent implementation of the same CLI surface, manifest schema, and safety rules, built soenv-synccan eventually ship as one static binary with no Node dependency. It passes the same golden conformance fixtures as the TypeScript side. It has not yet been run against a real 1Password Service Account, so treat it as fixture-verified, not production-proven.
Next steps
- Getting Started: prerequisites, a first manifest, and your first
validate/diff/push. - Usage: every command, flag, and exit code.
- Architecture: the provider contract, the six adapters, and the per-target protection rule.