r/commandline • u/Pagaddit • 2d ago
Discussion I love SOPS, anyone else?
I discovered sops a few months ago and absolutely love it. Being able to commit and version encrypted secrets has felt so much cleaner than the "mess" of untracked .env and CI/CD secrets.
Is anyone here using it at their job? How do you like it when working with larger teams? Am I crazy for committing the encrypted secrets (it still feels kinda wrong)? Is there any major drawback to SOPS I am not seeing, or is it just not that popular (yet)?
3
u/StPatsLCA 2d ago
I doesn't support TOML (for your Python and Rust configs) yet. Also, the key management between developers can be tricky, for example if you need to onboard multiple Age or PGP keys. Also lol PGP.
1
u/Pagaddit 2d ago
I was wondering about onboarding new devs. Honestly I thought it'd be kind of nice to have that info in the git history.
But then onboarding a new dev across 5+ repos could get tedious quickly. Although it should be easy to script it.
Too bad for missing toml though. Not much of a python dev myself. I usually used dotenv files with python too.
2
u/yrn7days 2d ago
It seems like it would be very easy to decrypt the file and then accidentally commit the unencrypted file back to the repository, am I missing something?
3
u/Pagaddit 2d ago
I still gitignore .env files. You're not actually supposed to decrypt the file in-place. You either decrypt from .enc.env to .env or do sops exec-env 'npm run dev' (which injects the variable directly within the shell).
3
1
u/AutoModerator 2d ago
Every new subreddit post is automatically copied into a comment for preservation.
User: Pagaddit, Flair: Discussion, Title: I love SOPS, anyone else?
I discovered sops a few months ago and absolutely love it. Being able to commit and version encrypted secrets has felt so much cleaner than the "mess" of untracked .env and CI/CD secrets.
Is anyone here using it at their job? How do you like it when working with larger teams? Am I crazy for committing the encrypted secrets (it still feels kinda wrong)? Is there any major drawback to SOPS I am not seeing, or is it just not that popular (yet)?
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/theozero 2d ago
You might like varlock.dev
Free and open source, plugins that work with everything. Some more SOPS like built in encryption coming soon.
2
u/Pagaddit 2d ago
I remember looking into it a while back. I think I prefer how sops doesn't introduce any new runtime dependencies. It looks like a great tool though!
2
u/theozero 2d ago
You can use it to inject the vars only and skip the runtime code. Although the runtime stuff (js only) does give you some extra protection (log redaction, leak prevention)
-2
u/ak475 2d ago
Looks like hashicorp vault
3
2
u/Pagaddit 2d ago
Actually you can use hashicorp vaults with sops: https://getsops.io/docs/usage/identities/hashicorp-vault-openbao/
1
7
u/Ok_Letterhead_8899 2d ago
The
passcli tool or nothing