Skip to main content

validate

Check that a service is ready to sync. validate never writes.

env-sync validate (--service <name> | --all) --env <env>

For each selected service, validate does these checks:

  1. Reads the 1Password item <source>/<env>. It fails if the item is missing or any field is empty.
  2. Runs any adapter key-name checks (for example, platform-reserved names).
  3. Calls each target's readCurrent for real, to prove that the target is reachable with your current credentials.
$ env-sync validate --service api --env dev
[api] OK: app-secrets/myapp/api/dev exists with fields: DATABASE_URL, API_KEY
[api] target ssm:/myapp/api: reachable
[api] target github-actions:myorg/myapp:dev: reachable

When a check fails, the service prints [<service>] Failed: <message> (secret values redacted) and the command exits 1:

[api] Failed: [api] app-secrets/myapp/api/dev has empty value(s) for field(s): API_KEY -- fix in 1Password before validate can pass

With --all, one failed service does not stop the others.

Exit codes (all commands)​

0 means success. 1 means any failure: a usage error, a manifest schema error, any service that throws, drift found, or a failed push. 1 is the only non-zero code, so do not branch on failure kinds by exit code. The one exception is diff --format json (see diff).