Aller au contenu principal

Local Env Secrets

Use Proton Pass for local-only secrets if you want to recreate .env quickly on a new machine.

This does not replace SOPS:

  • local development: Proton Pass
  • staging / production: infra/env/*.env.enc

Store one Proton Pass item containing the full local .env content.

Recommended item name:

aaperture/local-env

The item should contain the final .env file content in a text field you can print from the CLI.

Important:

  • Proton Pass CLI access depends on your Proton account
  • if your account is not yet allowed to use the CLI, use the export-file fallback below

Script​

Use:

PROTON_PASS_ENV_ITEM="aaperture/local-env" \
PROTON_PASS_ENV_CMD='pass-cli item view --item-title "{item}" --field note' \
bash scripts/render-local-env-from-proton.sh

Notes:

  • PROTON_PASS_ENV_CMD must print the full .env content to stdout
  • {item} is replaced automatically by the item name
  • the generated file is validated against .env.example

Make targets​

Create .env from Proton Pass:

make env-local-from-proton \
PROTON_PASS_ENV_ITEM="aaperture/local-env" \
PROTON_PASS_ENV_CMD='pass-cli item view --item-title "{item}" --field note'

Create .env, sync backend/.env and infra/.env:

make sync-env-from-proton \
PROTON_PASS_ENV_ITEM="aaperture/local-env" \
PROTON_PASS_ENV_CMD='pass-cli item view --item-title "{item}" --field note'

Create .env, sync env files, then start local Docker stack:

make dev-proton \
PROTON_PASS_ENV_ITEM="aaperture/local-env" \
PROTON_PASS_ENV_CMD='pass-cli item view --item-title "{item}" --field note'

Remove the local .env file:

make env-local-clean

Fallback without CLI access​

If Proton Pass CLI is installed but your account cannot use it yet, export the local env content manually and use a temporary file:

make env-local-from-proton \
PROTON_PASS_ENV_CMD='cat ~/Downloads/aaperture-local.env'

Then remove the temporary export file once .env is restored.

When changing variables​

If you add or remove a local variable:

  1. update .env.example
  2. update your Proton Pass local env item
  3. regenerate .env

Safety​

  • .env remains local and unversioned
  • do not commit Proton exports
  • keep your SSH deploy key and SOPS age key backed up separately