module

Secrets::Env

.env ↔ .env.age operations: file-to-file encryption with the current recipient roster, and exec which decrypts in memory and spawns a process with the parsed KEY=VALUE pairs injected into its environment — never writes the plaintext to disk.

The plaintext format is the de-facto Bourne-shell .env flavour:

comments

KEY=value KEY="quoted value" KEY='single-quoted' export KEY=value # export prefix accepted, ignored

Multi-line values, command substitution, and ${VAR} expansion are not supported. This is by design — a vault is a flat keystore, not a shell init file.

Instance methods

decrypt_file(enc_path : String, dest_path : String | Nil = nil) : String

Decrypt enc_path (a ciphertext .env.age) to dest_path (defaults to enc_path minus the .age suffix). The output is mode 0600. Use sparingly on a server — the goal of this shard is to not let plaintext .env files exist on disk; prefer Env.exec for the runtime case.

Source
encrypt_file(src_path : String, dest_path : String | Nil = nil) : String

Encrypt src_path (a plaintext .env) to dest_path (defaults to ${src_path}.age). The destination is mode 0600.

Source
exec(enc_path : String, command : String, args : Array(String)) : Int32

Decrypt enc_path in memory, parse it as .env, exec command with the parsed KEY=VALUE pairs added to its environment. Process.exec replaces the current process image — no plaintext is ever written to disk and the .env contents leave memory once the new image takes over. This is the recommended way to start a server-side service.

Returns Int32 only on failure (the exec branch never returns).

Source
parse(content : String) : Hash(String, String)

Parse .env-style content into a Hash. Whitespace is stripped, comments and empty lines are ignored, an optional leading export is allowed.

Source