7 ms·
Show HN: Envelope – A modern environment variable cli tool
Hey HN! I've built this cli tool to manage env variables of a project, but mostly for fun and to try out Rust and the clap crate.
I had this idea when I made a big mistake and broke some production stuff because I had a very messy .env file laying around in my project.
I was implementing new features for one of my projects and in my .env file I had the test database url commented out and the production one was not. Long story short, I applied migrations to the production database instead of my local test one and broke a lot of production APIs :')
I wanted a tool that could easily help me spot these issues before something bad happened, and so I built envelope for that reason.
Instead of a \.env(\..+)? file, I now use this tool to add variables to different configurations: dev, prod etc. and I feed them to the program I am executing on a one liner.
$ envelope init
$ envelope add dev db_url localhost:5432/postgres
$ envelope add dev db_username username
$ envelope add dev db_pwd pwd
$ export $(envelope list dev)
$ ./run.sh
This way I am explicitly exporting the dev environment without relying on the fact that everything is in order in my .env file (another approach would be to have a .env.dev file)
A very useful feature that I use quite a lot is the `check` command which is going to tell you which environment you have currently active
$ export $(envelope list dev)
$ envelope check
> dev
I don't think this tool is going to be useful to anybody, but I wanted to share this with you in case there is someone that can make good use of it or find particular scenarios where this could be used instead of .env files, either way I had a lot of fun building it
- cranberryturkey 2y agohow do I install the damn thing??
- mattrighetti 2y agoI'll copy the answer to a similar question in the issues: > I used to have a `brew tap` for it but I've removed it temporarily. To install it you can download the binary file in the latest release[0] and move it to your `/usr/local/bin` folder (on macOS this is what I'd do) or any other folder that is in your `$PATH`. [0]: https://github.com/mattrighetti/envelope/releases/latest https://github.com/mattrighetti/envelope/releases/latest
- cranberryturkey 2y agoCan we get an arch package?
- i4k 2y agoyep, do it!
- mattrighetti 2y agoAdded an aarch version to the release ci
- cranberryturkey 2y agoWhat's the package name?
- breck 2y agoI like it. Env variables should be a solved problem but no one has made the simplest general solution yet. Seems like you are on track. One suggestion: no need to use SQLite. Just develop a simple (and _lasting_), plain text DSL and save to a file. Here's one I made using your example. https://sdk.scroll.pub/designer/#parsers%0A%20valueCell%0A%20%20highlightScope%20string%0A%20variableNameCell%0A%20%20highlightScope%20keyword%0A%20%0A%20envelopeParser%0A%20%20root%0A%20%20description%20This%20is%20a%20stub%20for%20a%20DSL%20for%20Mattia%20Righetti'%20Envelope%20tool.%0A%20%20catchAllParser%20catchAllErrorParser%0A%20%20inScope%20variableParser%0A%20variableParser%0A%20%20catchAllCellType%20valueCell%0A%20%20cells%20variableNameCell%0A%20%20pattern%20%5BA-Z_%5D%2B%0A%20catchAllErrorParser%0A%20%20baseParser%20errorParser%0Asample%0A%20API_KEY%20your_api_key_here%0A%20AWS_ACCESS_KEY_ID%20your_access_key_id%0A%20DATABASE_URL%20postgres%3A%2F%2Fuser%3Apassword%40localhost%3A5432%2Fmydb%0A%20DEBUG_MODE%20true%0A%20SECRET_KEY%20mysecretkey123%0A%20SMTP_HOST%20smtp.example.com https://sdk.scroll.pub/designer/#parsers%0A%20valueCell%0A%2... I'm happy to chat more to nail that design if that would be helpful.
- gtirloni 2y agoI was thinking the same because how do you version control SQLite in git?
- skeledrew 2y agoI don't think you want your secrets committed...
- gtirloni 2y agoIt's common for projects to have placeholder values for dev/local environments. Environment variables aren't only for secrets (some say they should have never been).
- skeledrew 2y agoSure, but we've seen time and again where someone got hacked because secrets got committed, whether accidentally or deliberately. Why tempt fate with something that encourages committing of any env vars? The reason why we even pull these things out in the first place is because they're considered dynamic values. Otherwise we'd just hardcode them in a committed constants file.
- bloopernova 2y agoInteresting! Have you looked at mise-en-place at all? It's written in rust too, and might have some cool ideas to use: https://mise.jdx.dev/ https://mise.jdx.dev/
- tomwphillips 2y agoOf all the adjectives to use, why “modern”? Very common these days. I don’t get it.
- RadiozRadioz 2y agoMaybe it's a synonym for "Rust/Go instead of C/C++"
- toastercat 2y agoSame, except I take issue with the word "tool." Like a program? A library? A screwdriver? Very ambiguous. Very common these days as well. I don't get it.
- looperhacks 2y agoIt's explicitly called a "cli tool", not very ambiguous imo
- toastercat 2y agoNot quite. Could be Call Level Interface, Command Line Interface, Common Language Infrastructure, or Clintonville Municipal Airport which has the airport code of "CLI".
- superb_dev 2y agoAt this point you’re being intentionally obtuse. “CLI tool” is pretty non-ambiguous given the context
- bityard 2y agoI've noticed it's something a lot of Rust programs describe themselves as. Implying that software written in other programming languages is somehow vintage or obsolete, I guess.
- whateveracct 2y ago
- leetrout 2y agoA word of caution - this is a way to leak your secrets through your shell history: $ envelope add dev db_pwd pwd There are settings such that a command that starts with a space will not be saved in the history which would help here but I would be very careful about how you use this.
- mattrighetti 2y agoMine was a bad example :) the command also lets you input stuff from stdin for that very case
- bomewish 2y agoWhat’s the threat model? If an attacker has access to your shell history then don’t they then already have access to basically everything else?
- leetrout 2y agoNo, not necessarily. Compared to interactive prompts / processes, at a minimum ones that can help audit access (e.g. 1password), there is an immediate layer of defense missing when things are just sitting in plain text in the history. (Same extends to our beloved `.env` files.) If you do a lot of remote pairing or screen sharing then you also remove the risk of sharing on accident by searching or walking up through your command history.
- Kwpolska 2y agoThe docs don’t make it very obvious how are the environment variables actually applied. And I think .env files are much easier to manage and share. `envelope check` could be replaced with a CURRENT_ENV environment variable in an .env file. I can’t see how it would help avoid environment confusion more than $CURRENT_ENV displayed in your prompt would. (Or even better, not having production credentials on developers’ machines…)
- mattrighetti 2y ago> The docs don’t make it very obvious how are the environment variables actually applied. Actually, they are not applied. This is a tool that helps you manage them, you can see it as a replacement of .env files. > `envelope check` could be replaced with a CURRENT_ENV environment variable in an .env file Can you elaborate more on this? I've never used that tbh and I'm interested
- Kwpolska 2y ago> Actually, they are not applied. This is a tool that helps you manage them, you can see it as a replacement of .env files. The point of .env files is for tools (shells or libraries like dotenv) to read the file and actually use them. How do you do that with your tool, considering it uses a custom format? > Can you elaborate more on this? I've never used that tbh and I'm interested There is nothing special, just define a variable in .env, and then either echo it manually, or change your shell prompt to apply it.
- SeriousM 2y agoenvkey.com is also distributing environment variables
- twerkmonsta 2y agoyou probably don’t need sql
- mattrighetti 2y agoAgreed, sqlite is definitely overkill for this kind of task but it's also lightweight and fast, so why not?
- stephenr 2y ago> I had the test database url commented out and the production one was not. I feel like this is a giant red flag. Why on earth is your production database accessible from anywhere (ie your PC) without some kind of extra layer of security like a VPN or SSH tunnel?
- mattrighetti 2y agoThe production database that I'm talking about is a Postgres instance that is only available to me in my house for my side projects, it contains random stuff that can be queried through APIs that me and my family use with an app that works only when we are connected to our home LAN. Therefore I'm not paying as much attention when I do stuff with it as I would on a database that thousands of users rely on. Still, it sucks because it took quite some time to bring it back to a working state. Lesson learned
- another-dave 2y ago> This way I am explicitly exporting the dev environment without relying on the fact that everything is in order in my .env file (another approach would be to have a .env.dev file) What did you find lacking with the .env.dev approach? (Or if some tool doesn't support .env.dev could always symlink .env → .env.dev)
- mattrighetti 2y agoThe cons of that is that sometime I'd end up with 3 different files for different scenarios and in one particular case my tool only cared about the .env file, so I had to do a lot of `mv .env.dev .env` every time I had to switch to another env configuration.
- another-dave 2y agoBut running: ln -sf .env.dev .env doesn't seem any worse than running: envelope export dev ?
- Aeolun 2y agoWell… one is just a tad more readable.
- another-dave 2y agoMy personal approach is to favour more universal tools, so would prefer using symlinks & then adding a shell alias (or a package.json script) if I want to make it quicker to type. To each their own, though!
- skeledrew 2y agoHmm I fairly recently started saving variables which tend to be shared among multiple projects in a central location, grouped in sh files and sourcing as needed. This gives me an idea to improve that flow...
- globular-toast 2y agoSeems neat, but direnv can do more despite this claiming to be "modern".
- applgo443 2y agoWhen i deploy a webapp on azure, it expects me to put env variables in a file or their own tool (key value fields) where you can add env variables one by one. Is there a way to use envelope in places like those?
- nodesocket 2y agoAny plans to support encryption at rest?