keepenv
v0.0.1
Published
Keep .env files honest: drift checking, secret generation and rotation, cloud sync, and encrypted sharing. Built for humans and AI agents.
Maintainers
Readme
keepenv
Keep .env files honest.
Pre-alpha. The design is settled (docs/DESIGN.md); the code is being built. The npm package is a placeholder holding the name.
Every project has env files. Every team handles them slightly differently, and everywhere the same last mile rots: sample files drift from reality, secrets get pasted into cloud dashboards by hand, nobody remembers which vars a CI workflow needs, and keys get shared over Slack in plaintext.
keepenv is a tiny npx-able CLI that standardizes what you already do and automates that last mile. No server, no accounts, no runtime library, nothing to import. Your files stay plain files; the tool keeps them honest.
npx keepenv check # drift across env files, samples, environments, and CI
npx keepenv init # adopt in an existing project, idempotent
npx keepenv add # add a var everywhere, with typed generation
npx keepenv rotate # regenerate, push to cloud, run post-rotate hooks
npx keepenv sync # push to wrangler / GitHub Actions / AWS / Forgejo / Azure
npx keepenv share # encrypt an env file; the password travels separatelyBuilt for agents as well as humans
Gitignored files are invisible to version control and to AI coding agents, which rightly avoid reading credential files. So nothing notices when they rot. keepenv gives both parties a safe interface: every command reports names, lengths, and verdicts, never values, so agent transcripts and CI logs stay clean. init drops instructions into your CLAUDE.md / AGENTS.md so agents run check at session start and add variables through the CLI instead of guessing.
What it is not
Not a Vault, Doppler, or Infisical competitor: no value storage, no server, no team ACLs. The threat model is accidental leakage and drift, not a compromised workstation. If you need audit trails and access control, use a real secret manager; keepenv is for the other 90% of projects that just have files.
Status
Design: done, see docs/DESIGN.md. Build order: check first, then init and the manifest, then rotation, adapters, and sharing. Issues and convention requests welcome once the first release lands.
MIT, by Media Lantern.
