Workflow Commands
CLI commands for development workflow.
Workflow Commands
Commands that integrate with your development workflow.
run
Run a command with secrets injected as environment variables.
keyenv run [OPTIONS] -- <COMMAND>Options
| Option | Description |
|---|---|
-e, --env <ENV> | Environment (default: development) |
Examples
# Run npm start with secrets
keyenv run -- npm start
# Run with production secrets
keyenv run -e production -- node server.js
# Run any command
keyenv run -- python manage.py runserver
# Complex commands (use quotes)
keyenv run -- sh -c "echo $DATABASE_URL && npm test"How It Works
- Fetches secrets from the server
- Injects them as environment variables
- Runs your command with those variables
- Secrets are never written to disk
Use keyenv run when you want secrets available but don't want a .env file on disk.
diff
Show differences between local .env file and remote secrets.
keyenv diff [OPTIONS]Options
| Option | Description |
|---|---|
-e, --env <ENV> | Environment (default: development) |
Examples
keyenv diff
# Comparing .env with development:
# + NEW_LOCAL_KEY (local only)
# - REMOVED_KEY (remote only)
# ~ CHANGED_KEY (modified)
#
# + local only - remote only ~ modifiedOutput
| Symbol | Meaning |
|---|---|
+ | Key exists locally but not on server |
- | Key exists on server but not locally |
~ | Key exists in both but values differ |
JSON Output
keyenv diff --json{
"environment": "development",
"has_differences": true,
"differences": [
{ "key": "NEW_LOCAL_KEY", "status": "local_only" },
{ "key": "REMOVED_KEY", "status": "remote_only" },
{ "key": "CHANGED_KEY", "status": "modified" }
]
}history
Show version history for a secret.
keyenv history <KEY> [OPTIONS]Arguments
| Argument | Description |
|---|---|
KEY | The secret key to show history for |
Options
| Option | Description |
|---|---|
-e, --env <ENV> | Environment (default: development) |
-l, --limit <N> | Number of entries to show (default: 10) |
Examples
keyenv history DATABASE_URL
# History for DATABASE_URL (development):
# v3 2024-01-15 10:30 [email protected] postgres://prod...
# v2 2024-01-10 14:22 [email protected] postgres://staging...
# v1 2024-01-05 09:00 [email protected] postgres://dev...JSON Output
keyenv history DATABASE_URL --json{
"key": "DATABASE_URL",
"environment": "development",
"history": [
{
"version": 3,
"changed_at": "2024-01-15T10:30:00Z",
"changed_by": "[email protected]",
"value_preview": "postgres://prod..."
}
]
}Values are partially masked in the output. Use keyenv get to retrieve the full value.