validate
Check that a service is ready to sync. validate never writes.
env-sync validate (--service <name> | --all) --env <env>
For each selected service, validate does these checks:
- Reads the 1Password item
<source>/<env>. It fails if the item is missing or any field is empty. - Runs any adapter key-name checks (for example, platform-reserved names).
- Calls each target's
readCurrentfor real, to prove that the target is reachable with your current credentials.
$ env-sync validate --service api --env dev
[api] OK: app-secrets/myapp/api/dev exists with fields: DATABASE_URL, API_KEY
[api] target ssm:/myapp/api: reachable
[api] target github-actions:myorg/myapp:dev: reachable
When a check fails, the service prints [<service>] Failed: <message> (secret values redacted) and the command exits 1:
[api] Failed: [api] app-secrets/myapp/api/dev has empty value(s) for field(s): API_KEY -- fix in 1Password before validate can pass
With --all, one failed service does not stop the others.
Exit codes (all commands)
0 means success. 1 means any failure: a usage error, a manifest schema error, any service that throws, drift found, or a failed push. 1 is the only non-zero code, so do not branch on failure kinds by exit code. The one exception is diff --format json (see diff).