Secret Service

Keep your private keys in Linux Secret Service.

Keep the private key in your Linux secret store. You need secret-tool and an available Secret Service on your desktop session.

Store

Start with an encrypted .env and .env.keys, then move the key:

$ dotenvx native up

Dotenvx verifies the key in Linux Secret Service before removing it from .env.keys. Your .env stays encrypted.

For .env.production, add -f .env.production.

Run

$ dotenvx run -- node index.js

Dotenvx reads the key from Linux Secret Service before starting your app. Run under the same user account, with access to the secret store.

Move back

$ dotenvx native down

This moves the key back into .env.keys. Use dotenvx native pull to copy it back while keeping the stored key.

Keep .env.keys out of source control. See native commands for more.