envseal: secrets sealed in git
Encrypt .env secrets per-key, store them safely in git, inject them at runtime. Zero cloud, zero config, one binary.★ 0 on GitHub
Why envseal
Your team shares secrets over Slack. Someone copies .env from a colleague. A contractor leaves and nobody rotates the keys. envseal encrypts each secret individually using age cryptography. The encrypted vault lives in your git repo. Each team member has their own keypair — grant and revoke access per person, not per shared password.
How it works
- Encrypt secrets with
set,sync, orimport. - Decrypt at runtime with
runorpull— nothing touches disk in plaintext unless you ask for it. - Grant / revoke access per person — no shared passwords.
- Rotate keys without downtime.
Each secret is encrypted individually (X25519 + ChaCha20-Poly1305), so git diffon the vault shows only the one key that changed — never a wall of re-encrypted noise.
Install
curl -fsSL https://raw.githubusercontent.com/roman-kolpachev/envseal/main/scripts/install.sh | shBinaries for macOS, Linux, and Windows, or go install if you already have Go. Full instructions: github.com/roman-kolpachev/envseal.
vs. dotenvx / SOPS / Doppler
One ~10 MB binary, no bundled Node.js runtime, no KMS/IAM setup, no cloud account.envseal grant/revoke replace manually rotating a shared key or editing an IAM policy.
Built by the same team as our Atlassian plugins
envseal follows the same principle as every Jira and Confluence pluginwe ship: your data stays on infrastructure you control, not ours.
Further reading
- Why .env Files Are a Security Risk — Even After You Delete Them
- Common Types of Leaked Credentials
- Why Private Repositories Still Leak Secrets
- Secret Scanner Accuracy: Precision Is Not Enough
- Zero Trust Stops at the Confluence Page
- Deleting a Leaked Secret Does Not Revoke It
- The Secret Lifecycle Your Jira Workflow Is Missing
- Data Egress Is the Hidden Risk in Atlassian Security Apps
- Per-Secret Encryption Makes Git Reviews Safer
- AI Coding Assistants and the Secret-Sprawl Curve
- A Secrets Manager Does Not Stop Secret Sprawl
- A Two-Layer Secret Defense for Git and Atlassian
- Why Training Alone Does Not Prevent Secret Leaks
- Twelve-Factor Config Research — and Its Blind Spot for Secrets
- How Secrets Leak From CI/CD Logs — and Why Masking Doesn't Save You
- From Entropy to LLMs: What the Research Says About Detecting Secrets
- The Environment Variable Attack Surface: From /proc to Container Images
- Why Telling Developers Not to Commit Secrets Doesn't Work