DOTENV_FILE=.env.production

Decrypt your encrypted `.env.production` by setting `DOTENV_PRIVATE_KEY` and `DOTENV_FILE=.env.production` before dotenvx run.

Usage

$ touch .env.production
dotenvx set HELLO "production encrypted" -f .env.production
echo "console.log('Hello ' + process.env.HELLO)" > index.js

# check .env.keys for your privateKey
DOTENV_FILE=.env.production DOTENV_PRIVATE_KEY="122...0b8" dotenvx run -- node index.js
⟐ injected env (2) from .env.production
Hello production encrypted

Alternatively, this can be already set on your server or cloud provider.

You can also load this value from 1Password with op read.

DOTENV_FILE=.env.production DOTENV_PRIVATE_KEY="$(op read op://Engineering/my-app/DOTENV_PRIVATE_KEY)" dotenvx run -- node index.js

See Use dotenvx with 1Password.

Or load it from Bitwarden with bw get password.

export BW_SESSION="$(bw unlock --raw)"
DOTENV_FILE=.env.production DOTENV_PRIVATE_KEY="$(bw get password DOTENV_PRIVATE_KEY)" dotenvx run -- node index.js

See Use dotenvx with Bitwarden.

DOTENV_FILE=.env.production selects the file. DOTENV_PRIVATE_KEY supplies its matching decryption key.