Env-to-Vault
A tool to convert environment variables from ENV files to HashiCorp Vault Secret Engine format, with automatic key case conversion (uppercase to lowercase) and robust configuration management using Pydantic.
Features
- 🔄 Convert ENV files to Vault Secret Engine format
- 🔤 Automatic uppercase to lowercase key conversion
- ⚙️ Robust configuration management with Pydantic
- 🔐 Secure Vault integration with multiple authentication methods
- 🛠️ Command-line interface with validation and dry-run modes
Installation
Prerequisites
- Python 3.8+
- HashiCorp Vault server/cloud
- uv (recommended) or pip
Using uv (Recommended)
# Install uv if you haven't already
curl -LsSf https://astral.sh/uv/install.sh | sh
# Clone the repository
git clone <repository-url>
cd env-to-vault
# Install dependencies
uv sync
# Install the package in development mode
uv pip install -e .
Using pip
pip install env-to-vault
Quick Start
- Create a configuration file (
config.yaml):
vault:
url: "http://localhost:8200"
token: "your-vault-token"
secret_engine: "secret"
path_prefix: "env"
env_file:
path: ".env"
encoding: "utf-8"
- Run the conversion:
env-to-vault convert --config config.yaml
Configuration
Vault Configuration
url: Vault server URLtoken: Vault authentication tokensecret_engine: Secret engine name (default: "secret")path_prefix: Path prefix for secrets in Vault
Environment File Configuration
path: Path to the ENV fileencoding: File encoding (default: "utf-8")
Usage Examples
Basic Conversion
# Convert .env file to Vault
env-to-vault convert --env-file .env --vault-url http://localhost:8200 --vault-token your-token
Using Configuration File
# Use configuration file
env-to-vault convert --config config.yaml
Validation Mode
# Validate configuration without making changes
env-to-vault validate --config config.yaml
Verbose Output
# Show detailed output
env-to-vault convert --config config.yaml --verbose
Development
Setup Development Environment
# Install development dependencies
uv sync --group dev
# Run tests
uv run pytest
# Run linting
uv run black src tests
uv run flake8 src tests
# Run type checking
uv run mypy src
Project Structure
env-to-vault/
├── src/
│ └── env_to_vault/
│ ├── __init__.py
│ ├── cli.py
│ ├── config.py
│ ├── parser.py
│ └── vault.py
├── tests/
├── examples/
├── pyproject.toml
└── README.md
License
MIT License - see LICENSE file for details.
Metadata
Release files for env-to-vault 0.1.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| env_to_vault-0.1.4.tar.gz | 40.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| env_to_vault-0.1.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 50.5 kB
Release files / env_to_vault-0.1.4.tar.gz
| Download URL | env_to_vault-0.1.4.tar.gz |
|---|---|
| Size | 40.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
470e21d34b0e810b147778bab7285cf4e33e14c92e4d096c3b8123951aa0e18b
|
|
BLAKE2b-256 checksum How to use checksums |
a08e09e6a993ca7870fb7351024587ba5e9c542eb401f5595c846943857a6834
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.8.9
|
Release files / env_to_vault-0.1.4-py3-none-any.whl
| Download URL | env_to_vault-0.1.4-py3-none-any.whl |
|---|---|
| Size | 10.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f79fe5269ac0c2ed648de67bfe6b2386bbeaa285a7cf34236cf0081cf42feed5
|
|
BLAKE2b-256 checksum How to use checksums |
90274fc0b8a6b02b89719cc29b20e471d3f0cdc1cfdbfb9238295c4f3a342ec6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.8.9
|