Skip to main content

What is env-sync?

env-sync is a command-line tool that keeps secrets in sync between 1Password and the platforms your services actually run on. You describe each service once in a secrets.manifest.yml: where its secrets live in 1Password, and which targets need them. env-sync then diffs, validates, or pushes those values to six target platforms:

  • AWS SSM Parameter Store (ssm)
  • Local dotenv files (dotenv)
  • Vercel project environment variables (vercel)
  • Render service environment variables (render)
  • CapRover app environment variables (caprover, read-only by default)
  • GitHub Actions repository and environment secrets (github-actions)

1Password stays the single source of truth. env-sync diff shows you where a platform has drifted from it (using fingerprints, never raw values), and env-sync push --apply fixes that drift. Every push that cannot be proven safe asks for confirmation first, and it fails closed in CI. The original script that env-sync was ported from had no such gate.

Where it stands today​

env-sync is an internal tool in a private repository. It has no published package or binary release yet. To install it, clone the repository and build it (see Getting Started). A real distribution mechanism, such as an npm package or GitHub Releases binaries, is an open follow-up.

There are two implementations of the same contract:

  • TypeScript (apps/cli + packages/core): the primary implementation today. It is a faithful port of the original secrets-source-of-truth scripts, and all 191 of the original tests carry over unchanged.
  • Go (go/): an independent implementation of the same CLI surface, manifest schema, and safety rules, built so env-sync can eventually ship as one static binary with no Node dependency. It passes the same golden conformance fixtures as the TypeScript side. It has not yet been run against a real 1Password Service Account, so treat it as fixture-verified, not production-proven.

Next steps​

  • Getting Started: prerequisites, a first manifest, and your first validate / diff / push.
  • Usage: every command, flag, and exit code.
  • Architecture: the provider contract, the six adapters, and the per-target protection rule.