Secrets::Env
.env ↔ .env.age operations: file-to-file encryption with the
current recipient roster, and exec which decrypts in memory and
spawns a process with the parsed KEY=VALUE pairs injected into
its environment — never writes the plaintext to disk.
The plaintext format is the de-facto Bourne-shell .env flavour:
comments
KEY=value
KEY="quoted value"
KEY='single-quoted'
export KEY=value # export prefix accepted, ignored
Multi-line values, command substitution, and ${VAR} expansion are not supported. This is by design — a vault is a flat keystore, not a shell init file.
Instance methods
Decrypt enc_path (a ciphertext .env.age) to dest_path
(defaults to enc_path minus the .age suffix). The output is
mode 0600. Use sparingly on a server — the goal of this shard
is to not let plaintext .env files exist on disk; prefer
Env.exec for the runtime case.
Encrypt src_path (a plaintext .env) to dest_path (defaults
to ${src_path}.age). The destination is mode 0600.
Decrypt enc_path in memory, parse it as .env, exec command
with the parsed KEY=VALUE pairs added to its environment.
Process.exec replaces the current process image — no
plaintext is ever written to disk and the .env contents leave
memory once the new image takes over. This is the recommended
way to start a server-side service.
Returns Int32 only on failure (the exec branch never returns).