EnvGuard
A zero-dependency, developer-friendly CLI and Python library to audit, validate, diff, and safely synchronize environment variables across development, staging, and CI/CD pipelines.
Why EnvGuard?
Environment drift is one of the most frequent causes of broken local builds and failed production deployments:
- Developers add new keys in
.envbut forget to update.env.example. - Team members pull recent changes and crash because their local
.envis missing new required keys. - Placeholders like
API_KEY=<YOUR_KEY_HERE>orDEBUG=TODOaccidentally get deployed. - Incorrect types (e.g.
PORT=fooinstead of a valid integer) crash services at runtime.
EnvGuard solves this instantly with zero external dependencies, human-friendly colorized terminal reports, and CI-ready exit codes.
Features
- Automatic Audit & Validation: Compares
.envwith.env.exampleto detect missing keys, unpopulated secrets, and dummy placeholders. - Safe Synchronization: Automatically syncs missing keys into your
.envwithout overwriting existing local values. - Secret-Safe Template Generation: Creates
.env.examplefrom your.env, automatically masking sensitive secrets (API_KEY,PASSWORD,JWT_SECRET, etc.). - Rich Schema Types: Validate types, ports (1-65535), URLs, emails, JSON strings, enums, numbers, and custom regex.
- CI/CD Ready: Exits with deterministic status codes (
0for success,1for missing/invalid keys,2for syntax/file errors). - Zero External Dependencies: Runs on standard Python 3.9+ standard library.
Installation
# Install locally in editable mode
pip install -e .
# Or install directly with pip
pip install envguard-tools
CLI Usage
1. Audit Environment (check)
Check if .env has all variables defined in .env.example and contains no unresolved placeholders:
envguard check
Output:
EnvGuard Audit Report
Comparing: .env vs template .env.example
X Missing Variables (1):
- STRIPE_WEBHOOK_SECRET (defined in .env.example:14)
! Empty or Unresolved Placeholders (1):
! DATABASE_URL: placeholder '<YOUR_DB_URL>' (.env:3)
[+] 12 variables valid and populated.
X Environment check failed. Fix issues above before proceeding.
2. Synchronize Missing Variables (sync)
Automatically append missing keys from .env.example to your .env without modifying existing values:
# Preview changes without writing
envguard sync --dry-run
# Synchronize missing keys
envguard sync
3. Compare Environments (diff)
View a breakdown of matching, missing, extra, and placeholder variables:
envguard diff -e .env.staging -x .env.production
4. Generate Safe .env.example (init)
Generate a clean template from an existing .env with all sensitive credentials automatically masked:
envguard init -e .env -o .env.example
Python SDK Usage
You can also use EnvGuard programmatically in your application startup or test suites:
from envguard import EnvValidator, Rule, parse_env_file
# Define schema validation rules
validator = EnvValidator([
Rule("PORT", type="port", required=True),
Rule("DEBUG", type="boolean", required=True),
Rule("DATABASE_URL", type="url", required=True),
Rule("ENVIRONMENT", type="enum", choices=["development", "staging", "production"]),
Rule("MAX_CONNECTIONS", type="integer", min_value=1, max_value=100),
])
# Load and validate
env = parse_env_file(".env")
result = validator.validate(env)
if not result.is_valid:
for issue in result.issues:
print(f"[{issue.issue_type.upper()}] {issue.message}")
raise SystemExit(1)
CI/CD Integration
Add EnvGuard to your GitHub Actions workflow to block PRs with missing environment variables:
- name: Verify Environment Variables
run: |
pip install envguard-tools
envguard check --strict
Running Tests
Run the full test suite across all modules:
python -m unittest discover -s tests -v
Development
Run the full test suite:
python -m unittest discover -s tests -v
Measure coverage (must stay ≥85%):
pip install -r requirements-dev.txt
coverage run -m unittest discover -s tests
coverage report
Type-check:
mypy envguard
Publish a new release:
pip install -r requirements-dev.txt
python -m build
twine upload dist/*
License
Distributed under the MIT License. Copyright (c) 2026 Faizan.
Metadata
Release files for envguard-tools 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| envguard_tools-0.1.1.tar.gz | 16.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| envguard_tools-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 30.6 kB
Release files / envguard_tools-0.1.1.tar.gz
| Download URL | envguard_tools-0.1.1.tar.gz |
|---|---|
| Size | 16.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5a48fd0ee7abf2b9476119679b2306b89c800699261e6c888e2152bddbaa04ef
|
|
BLAKE2b-256 checksum How to use checksums |
8f549797f134d20db1fa1ae8f198c1d0b9028746b2ca55df24961582701f79ea
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.14
|
Release files / envguard_tools-0.1.1-py3-none-any.whl
| Download URL | envguard_tools-0.1.1-py3-none-any.whl |
|---|---|
| Size | 13.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
05acc35830094f3915e8830da809d265755360897d0cacb12e79ecf40e10673c
|
|
BLAKE2b-256 checksum How to use checksums |
f272e0c57338ec45aa7e59c7a4879673c65d0dd6c539892df2c1a95b80014196
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.14
|