posit-connect-secrets-manager
A terminal UI for bulk-managing environment variables across Posit Connect content items.
What it does
Posit Connect stores environment variables per content item. Managing them one at a time through the web UI is tedious at scale. This tool lets you:
- Browse all your content items and their environment variables
- Maintain a local vault of key/value pairs (stored as JSON)
- Safe-merge sync (
Ctrl+U) — pushes vault values into each project's env vars without touching keys the vault doesn't know about and without adding new keys to projects that don't already define them - Filter any list with fuzzy search
- Blacklist projects or individual variables from sync
- Edit values in
$EDITORfor multi-line or sensitive content
Install
uv tool install posit-connect-secrets-manager
Or from source (requires Rust toolchain):
uv tool install git+https://github.com/KalebJS/posit-connect-secrets-manager
# or
cargo install --git https://github.com/KalebJS/posit-connect-secrets-manager
Getting started
Launch the TUI:
posit-secrets
On first launch you'll land on the Projects page. Use j/k in the sidebar to navigate to Settings, then press l or Enter to enter the settings pane and fill in your server URL and API key. Press h or Esc to return to the sidebar, then Ctrl+P to fetch your content items — they'll populate the project list within a few seconds.
Once projects are loaded, navigate to Env Vars in the sidebar to see an aggregated list of every environment variable key across all your projects, alongside the matching value from your vault. Use Vault to manage those vault entries. When your vault is ready, press Ctrl+U from anywhere to sync vault values into every project that already has a matching key.
Pages
| Page | Description |
|---|---|
| Projects | Browse content items and their env vars; expand to inspect, add, delete, or blacklist individual vars |
| Env Vars | Aggregated view of all env var keys across projects, showing which have vault values |
| Vault | Manage the local key/value store that gets synced to projects |
| Settings | Server URL, API key, vault path, and theme |
Configuration
Config is saved to ~/.config/posit-secrets/config.toml.
| Field | Description |
|---|---|
| Server URL | Your Posit Connect base URL (e.g. https://connect.example.com) |
| API Key | A Posit Connect API key with write access to your content |
| Vault Path | Path to the local JSON vault file (default: ~/.config/posit-secrets/vault.json) |
| Theme | Color theme — cycle with Enter on the theme row |
Corporate TLS: set SSL_CERT_FILE (path to a PEM file) or SSL_CERT_DIR (directory of *.pem files) to inject custom CA certificates.
Keybindings
Global
| Key | Action |
|---|---|
Tab |
Toggle sidebar / content focus |
q / Ctrl+C |
Quit |
Ctrl+P |
Refresh project list from Posit Connect |
Ctrl+U |
Safe-merge sync vault → all projects (shows confirmation) |
Navigation
| Key | Action |
|---|---|
j / ↓ |
Move down |
k / ↑ |
Move up |
h / ← / Esc |
Return to sidebar |
l / → / Enter |
Enter content pane (from sidebar) |
g |
Jump to top |
G |
Jump to bottom |
f / / |
Open fuzzy filter |
F |
Clear filter |
Projects page
| Key | Action |
|---|---|
Enter / Space |
Expand / collapse project to show its env vars |
x |
On a project row: toggle project in/out of sync whitelist. On a var row: toggle var exclusion for that project |
a |
Add an env var to the selected project (fuzzy-picks from vault keys) |
d |
Delete the selected env var from the project |
Env Vars page
| Key | Action |
|---|---|
Enter / Space |
Open popup showing which projects use the selected var |
e / E |
Open the selected var's vault value in $EDITOR |
Vault page
| Key | Action |
|---|---|
n |
New entry (opens key field for editing) |
e / Enter |
Edit value of selected entry |
E |
Open value in $EDITOR |
d / Delete |
Delete selected entry |
Settings page
| Key | Action |
|---|---|
e / Enter |
Edit selected field (theme field cycles values instead) |
Esc |
Cancel edit |
Safe-merge sync
Ctrl+U iterates every non-blacklisted content item and, for each one:
- Fetches current env vars from the Connect API
- Overlays vault values only for keys that already exist in the project
- PATCHes the merged set back
It never adds new environment variables to a project that doesn't already define them, and never deletes existing ones. Safe to run repeatedly.
License
MIT
Metadata
Release files for posit-connect-secrets-manager 0.5.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| posit_connect_secrets_manager-0.5.1.tar.gz | 55.3 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| posit_connect_secrets_manager-0.5.1-py3-none-win_amd64.whl | Python 3 | none | Windows x86-64 | Details |
| posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Python 3 | none | Linux glibc 2.17+ x86-64 | Details |
| posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl | Python 3 | none | Linux glibc 2.17+ ARM64 | Details |
| posit_connect_secrets_manager-0.5.1-py3-none-macosx_11_0_arm64.whl | Python 3 | none | macOS 11.0+ ARM64 | Details |
| posit_connect_secrets_manager-0.5.1-py3-none-macosx_10_12_x86_64.whl | Python 3 | none | macOS 10.12+ x86-64 | Details |
Total release size: 11.4 MB
Release files / posit_connect_secrets_manager-0.5.1.tar.gz
| Download URL | posit_connect_secrets_manager-0.5.1.tar.gz |
|---|---|
| Size | 55.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4465ba51b4620bf8c84a623d93f66441abd8cc3a88dacec580b445f6cfe0d13f
|
|
BLAKE2b-256 checksum How to use checksums |
e39a2c6f20cac5a124022f6c47b2731ed355885501cfb7387dab89126ace6252
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.
Transparency logRelease files / posit_connect_secrets_manager-0.5.1-py3-none-win_amd64.whl
| Download URL | posit_connect_secrets_manager-0.5.1-py3-none-win_amd64.whl |
|---|---|
| Size | 2.2 MB |
| Tags | Python 3 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
1d3bd511dabcc460ad7449150a63e416774017708710e8dd4b57268ddfbb4221
|
|
BLAKE2b-256 checksum How to use checksums |
420f8b5190664857d7ca5c7791302caa3af92205e362335d26e8ec390d7f4968
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.
Transparency logRelease files / posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 2.4 MB |
| Tags | Linux glibc 2.17+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
e2c21bb73c60f24564e87f51bb0e8e98e4bb76cb3c633550619fe2bb474cb20f
|
|
BLAKE2b-256 checksum How to use checksums |
d96bde0d505b28750960856d050f5c23bb61e7ea9c46079a08a107f3b9a352c6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.
Transparency logRelease files / posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 2.2 MB |
| Tags | Linux glibc 2.17+ ARM64 Python 3 |
|
SHA-256 checksum How to use checksums |
06f0667b8317b6c4d2fb9e7e3d2c286143ed56cce54f553b5ccfacb595d4f547
|
|
BLAKE2b-256 checksum How to use checksums |
6eb763c33e96416068403f3e840c89d7ff794c1206562ae336726e5f6d4aaf4f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.
Transparency logRelease files / posit_connect_secrets_manager-0.5.1-py3-none-macosx_11_0_arm64.whl
| Download URL | posit_connect_secrets_manager-0.5.1-py3-none-macosx_11_0_arm64.whl |
|---|---|
| Size | 2.2 MB |
| Tags | Python 3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
e871be995a372aceff673b30f13e076e40c3f2a192c59fc668c2b42b99c3848f
|
|
BLAKE2b-256 checksum How to use checksums |
2951197f83a3aed4c6ccd06395c91a46d95dc8db4158a714f971b48d4dafe4ca
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.
Transparency logRelease files / posit_connect_secrets_manager-0.5.1-py3-none-macosx_10_12_x86_64.whl
| Download URL | posit_connect_secrets_manager-0.5.1-py3-none-macosx_10_12_x86_64.whl |
|---|---|
| Size | 2.3 MB |
| Tags | Python 3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
86edc7e4f2378366a25b499d8b80dca015862f2bc17b20c2432bbb6a451d1bcf
|
|
BLAKE2b-256 checksum How to use checksums |
5570a2f3b6e262c6b97b1465eb919d8e4540a6dde91ee990a9b4d366ddca3b4c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.
Transparency log