Local Env Secrets
Use Proton Pass for local-only secrets if you want to recreate .env quickly on a new machine.
This does not replace SOPS:
- local development: Proton Pass
- staging / production:
infra/env/*.env.enc
Recommended setup
Store one Proton Pass item containing the full local .env content.
Recommended item name:
aaperture/local-env
The item should contain the final .env file content in a text field you can print from the CLI.
Important:
- Proton Pass CLI access depends on your Proton account
- if your account is not yet allowed to use the CLI, use the export-file fallback below
Script
Use:
PROTON_PASS_ENV_ITEM="aaperture/local-env" \
PROTON_PASS_ENV_CMD='pass-cli item view --item-title "{item}" --field note' \
bash scripts/render-local-env-from-proton.sh
Notes:
PROTON_PASS_ENV_CMDmust print the full.envcontent to stdout{item}is replaced automatically by the item name- the generated file is validated against
.env.example
Make targets
Create .env from Proton Pass:
make env-local-from-proton \
PROTON_PASS_ENV_ITEM="aaperture/local-env" \
PROTON_PASS_ENV_CMD='pass-cli item view --item-title "{item}" --field note'
Create .env, sync backend/.env and infra/.env:
make sync-env-from-proton \
PROTON_PASS_ENV_ITEM="aaperture/local-env" \
PROTON_PASS_ENV_CMD='pass-cli item view --item-title "{item}" --field note'
Create .env, sync env files, then start local Docker stack:
make dev-proton \
PROTON_PASS_ENV_ITEM="aaperture/local-env" \
PROTON_PASS_ENV_CMD='pass-cli item view --item-title "{item}" --field note'
Remove the local .env file:
make env-local-clean
Fallback without CLI access
If Proton Pass CLI is installed but your account cannot use it yet, export the local env content manually and use a temporary file:
make env-local-from-proton \
PROTON_PASS_ENV_CMD='cat ~/Downloads/aaperture-local.env'
Then remove the temporary export file once .env is restored.
When changing variables
If you add or remove a local variable:
- update
.env.example - update your Proton Pass local env item
- regenerate
.env
Safety
.envremains local and unversioned- do not commit Proton exports
- keep your SSH deploy key and SOPS age key backed up separately