Bitwarden
Keep your private keys in Bitwarden.
Store the private key in Bitwarden. Your encrypted .env stays in your project.
Store
Install the Bitwarden CLI (bw) and sign in:
$ bw login
Start with an encrypted .env and .env.keys, then move the key:
$ dotenvx bitwarden up
Dotenvx prompts to unlock your vault if needed. It creates a personal vault item, verifies it, and removes the key from .env.keys. A reference to the item stays in your local Dotenvx settings.
For .env.production, add -f .env.production.
Run
$ dotenvx run -- node index.js
Dotenvx reads the key through bw before starting your app. For noninteractive use, provide an unlocked BW_SESSION.
Move back
$ dotenvx bitwarden down
This writes the key to .env.keys and deletes its Bitwarden item. Use dotenvx bitwarden pull to copy it back without deleting the item.
Keep .env.keys out of source control. See Bitwarden commands for more.