Skip to main content

ENVLock

PyPI version Python versions codecov License Build Status Snyk Vulnerabilities

A secure CLI tool for encrypting, decrypting, shredding, and rotating secrets files (e.g., .env) using strong symmetric encryption (Fernet/AES).

Features

  • Encrypt (lock) and decrypt (unlock) files with a 256-bit key
  • Key can be provided as hex, base64, or via the ENVLOCK_ENCRYPTION_KEY environment variable
  • Secure file shredding (overwriting and deleting original file)
  • Key rotation (renew) for re-encrypting with a new key
  • Short and long CLI options for all commands

Installation

Requires Python 3.8+ and the cryptography and click packages:

pip install cryptography click

Usage

Lock a file (encrypt)

envlock lock [-f FILE] [-k KEY] [-h] [-s]
  • -f, --file : File to lock (default: .env)
  • -k, --key : Encryption key (hex or base64). If omitted, uses ENVLOCK_ENCRYPTION_KEY or generates a new key.
  • -h, --hide-key : Hide generated key output (default: show)
  • -s, --shred : Securely delete original file after locking

Example:

envlock lock -f .env -s

Unlock a file (decrypt)

envlock unlock [-f FILE] -k KEY
  • -f, --file : File to unlock (default: .env.locked)
  • -k, --key : Encryption key (hex or base64, required)

Example:

envlock unlock -f .env.locked -k <key>

Renew (rotate) encryption key

envlock renew [-f FILE] --old-key OLDKEY [--new-key NEWKEY] [-h]
  • -f, --file : File to renew (default: .env.locked)
  • --old-key : Current encryption key (hex or base64, required)
  • --new-key : New encryption key (hex or base64, optional; if omitted, a new key is generated)
  • -h, --hide-key : Hide generated new key output (default: show)

Example:

envlock renew --old-key <oldkey>

Key Management

  • Keys are 32 bytes (64 hex chars or 32 bytes base64)
  • Store keys securely (never in your repo)
  • You can use the ENVLOCK_ENCRYPTION_KEY environment variable for automation

Security Notes

  • The encrypted file can be public; only the key must remain secret
  • Never print or log the key in CI/CD logs
  • Use secure deletion (--shred) for sensitive files
  • Rotate keys regularly and after any suspected compromise

Shell Completion

envlock supports shell completion for bash, zsh, and fish. To enable it, run:

eval "$(_ENVLOCK_COMPLETE=source_bash envlock)"  # for bash
eval "$(_ENVLOCK_COMPLETE=source_zsh envlock)"   # for zsh
eval "$(_ENVLOCK_COMPLETE=source_fish envlock)"  # for fish

Add the appropriate line to your shell profile to enable completion permanently.

Alternative Installation Methods

macOS/Linux

You can create a Homebrew formula for envlock or use pipx:

pipx install envlock

Windows

Install with pip or pipx:

pip install envlock
# or
pipx install envlock

Troubleshooting

  • Upload to PyPI/TestPyPI fails with 400 Bad Request:
    • Ensure your version is unique and not already uploaded.
    • Check your pyproject.toml for required fields.
    • Delete the dist/ directory before building.
  • Key errors:
    • Make sure your key is 32 bytes (64 hex chars or 32 bytes base64).
    • If using ENVLOCK_ENCRYPTION_KEY, ensure it is set in your environment.
  • Permission errors:
    • Run the CLI with appropriate permissions for file access.

FAQ

Q: Can I use envlock for files other than .env? A: Yes, you can lock/unlock any file by specifying the -f option.

Q: Is the encrypted file safe to store in version control? A: Yes, as long as you keep the key secret.

Q: How do I rotate my encryption key? A: Use the renew command with --old-key and optionally --new-key.

Q: How do I securely delete the original file? A: Use the --shred option with the lock command.

License

MIT

Metadata

Release files for envlock 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for envlock 1.0.0
File Size Uploaded
envlock-1.0.0.tar.gz 13.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for envlock 1.0.0
File Interpreter ABI Platform
envlock-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 20.8 kB

Release files / envlock-1.0.0.tar.gz

Download URL envlock-1.0.0.tar.gz
Size 13.3 kB
Tags Source
SHA-256 checksum
How to use checksums
22688d48674fb419f17506d554ec4e6c81cfd0357e9d2d831474e10c45a343a8
BLAKE2b-256 checksum
How to use checksums
f226fc2f45c51c19c4f73e0b4515191670bc6efd59ca8cade4d6befd5b4a108a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 27, 2025.

Transparency log

Release files / envlock-1.0.0-py3-none-any.whl

Download URL envlock-1.0.0-py3-none-any.whl
Size 7.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d175d14bacb0b8079989ea620939f1a2390627eb3159efe949e8cbddc2c28cf9
BLAKE2b-256 checksum
How to use checksums
e1f0152ec374495144fdfbe917c981a29bb59171993784a317f048adfee52e7f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 27, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page