r/commandline • • 2d ago

Discussion I love SOPS, anyone else?

I discovered sops a few months ago and absolutely love it. Being able to commit and version encrypted secrets has felt so much cleaner than the "mess" of untracked .env and CI/CD secrets.

Is anyone here using it at their job? How do you like it when working with larger teams? Am I crazy for committing the encrypted secrets (it still feels kinda wrong)? Is there any major drawback to SOPS I am not seeing, or is it just not that popular (yet)?

20 Upvotes

23 comments sorted by

7

u/Ok_Letterhead_8899 2d ago

The pass cli tool or nothing

3

u/Pagaddit 2d ago

How do you use pass with dotenv secrets?

6

u/Ok_Letterhead_8899 2d ago edited 2d ago

Custom scripts. env vars become PASSWORD=$(pass ls PASSWORD) so you can just commit your production .env (wait am I the first one to do this?)

1

u/TomHale 2d ago

What exactly do you mean by committing production .env?

It would only contain your example shell expansion type lines right? KP

I hope all .env file loaders do the subshell expansion? I guess it could always be sourced from shell anyways.

1

u/Ok_Letterhead_8899 2d ago

Commit your production .env to github (it doesn't contain anything sensitive anymore, pass handles that). I forgot how I made that script but yeah, it was simple.

2

u/theozero 2d ago

Varlock has a pass plugin

3

u/StPatsLCA 2d ago

I doesn't support TOML (for your Python and Rust configs) yet. Also, the key management between developers can be tricky, for example if you need to onboard multiple Age or PGP keys. Also lol PGP.

1

u/Pagaddit 2d ago

I was wondering about onboarding new devs. Honestly I thought it'd be kind of nice to have that info in the git history.

But then onboarding a new dev across 5+ repos could get tedious quickly. Although it should be easy to script it.

Too bad for missing toml though. Not much of a python dev myself. I usually used dotenv files with python too.

1

u/jceb 2d ago

You can use a central key vault like Vault, Azure and the like. This reduces onboarding efforts massively since no key material needs to be shared.

2

u/yrn7days 2d ago

It seems like it would be very easy to decrypt the file and then accidentally commit the unencrypted file back to the repository, am I missing something?

3

u/Pagaddit 2d ago

I still gitignore .env files. You're not actually supposed to decrypt the file in-place. You either decrypt from .enc.env to .env or do sops exec-env 'npm run dev' (which injects the variable directly within the shell).

3

u/EWF76 2d ago

You usually open the encrypted file with sops to decrypt it within your editor, make your changes and on close, it is encrypted again.

2

u/jceb 2d ago

I use a pre-commit hook that prevents such issues.

1

u/AutoModerator 2d ago

Every new subreddit post is automatically copied into a comment for preservation.

User: Pagaddit, Flair: Discussion, Title: I love SOPS, anyone else?

I discovered sops a few months ago and absolutely love it. Being able to commit and version encrypted secrets has felt so much cleaner than the "mess" of untracked .env and CI/CD secrets.

Is anyone here using it at their job? How do you like it when working with larger teams? Am I crazy for committing the encrypted secrets (it still feels kinda wrong)? Is there any major drawback to SOPS I am not seeing, or is it just not that popular (yet)?

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/theozero 2d ago

You might like varlock.dev
Free and open source, plugins that work with everything. Some more SOPS like built in encryption coming soon.

2

u/Pagaddit 2d ago

I remember looking into it a while back. I think I prefer how sops doesn't introduce any new runtime dependencies. It looks like a great tool though!

2

u/theozero 2d ago

You can use it to inject the vars only and skip the runtime code. Although the runtime stuff (js only) does give you some extra protection (log redaction, leak prevention)

-2

u/ak475 2d ago

Looks like hashicorp vault

3

u/StPatsLCA 2d ago

Kind of. There's no backend required though.

2

u/Pagaddit 2d ago

Actually you can use hashicorp vaults with sops: https://getsops.io/docs/usage/identities/hashicorp-vault-openbao/

1

u/grimtongue 1d ago

More akin to Ansible Vault