envseal: secrets sealed in git

Encrypt .env secrets per-key, store them safely in git, inject them at runtime. Zero cloud, zero config, one binary.★ 0 on GitHub

Why envseal

Your team shares secrets over Slack. Someone copies .env from a colleague. A contractor leaves and nobody rotates the keys. envseal encrypts each secret individually using age cryptography. The encrypted vault lives in your git repo. Each team member has their own keypair — grant and revoke access per person, not per shared password.

How it works

Each secret is encrypted individually (X25519 + ChaCha20-Poly1305), so git diffon the vault shows only the one key that changed — never a wall of re-encrypted noise.

Install

curl -fsSL https://raw.githubusercontent.com/roman-kolpachev/envseal/main/scripts/install.sh | sh

Binaries for macOS, Linux, and Windows, or go install if you already have Go. Full instructions: github.com/roman-kolpachev/envseal.

vs. dotenvx / SOPS / Doppler

One ~10 MB binary, no bundled Node.js runtime, no KMS/IAM setup, no cloud account.envseal grant/revoke replace manually rotating a shared key or editing an IAM policy.

Built by the same team as our Atlassian plugins

envseal follows the same principle as every Jira and Confluence pluginwe ship: your data stays on infrastructure you control, not ours.

Further reading