Skip to main content

posit-connect-secrets-manager

A terminal UI for bulk-managing environment variables across Posit Connect content items.

Rust License

What it does

Posit Connect stores environment variables per content item. Managing them one at a time through the web UI is tedious at scale. This tool lets you:

  • Browse all your content items and their environment variables
  • Maintain a local vault of key/value pairs (stored as JSON)
  • Safe-merge sync (Ctrl+U) — pushes vault values into each project's env vars without touching keys the vault doesn't know about and without adding new keys to projects that don't already define them
  • Filter any list with fuzzy search
  • Blacklist projects or individual variables from sync
  • Edit values in $EDITOR for multi-line or sensitive content

Install

uv tool install posit-connect-secrets-manager

Or from source (requires Rust toolchain):

uv tool install git+https://github.com/KalebJS/posit-connect-secrets-manager
# or
cargo install --git https://github.com/KalebJS/posit-connect-secrets-manager

Getting started

Launch the TUI:

posit-secrets

On first launch you'll land on the Projects page. Use j/k in the sidebar to navigate to Settings, then press l or Enter to enter the settings pane and fill in your server URL and API key. Press h or Esc to return to the sidebar, then Ctrl+P to fetch your content items — they'll populate the project list within a few seconds.

Once projects are loaded, navigate to Env Vars in the sidebar to see an aggregated list of every environment variable key across all your projects, alongside the matching value from your vault. Use Vault to manage those vault entries. When your vault is ready, press Ctrl+U from anywhere to sync vault values into every project that already has a matching key.

Pages

Page Description
Projects Browse content items and their env vars; expand to inspect, add, delete, or blacklist individual vars
Env Vars Aggregated view of all env var keys across projects, showing which have vault values
Vault Manage the local key/value store that gets synced to projects
Settings Server URL, API key, vault path, and theme

Configuration

Config is saved to ~/.config/posit-secrets/config.toml.

Field Description
Server URL Your Posit Connect base URL (e.g. https://connect.example.com)
API Key A Posit Connect API key with write access to your content
Vault Path Path to the local JSON vault file (default: ~/.config/posit-secrets/vault.json)
Theme Color theme — cycle with Enter on the theme row

Corporate TLS: set SSL_CERT_FILE (path to a PEM file) or SSL_CERT_DIR (directory of *.pem files) to inject custom CA certificates.

Keybindings

Global

Key Action
Tab Toggle sidebar / content focus
q / Ctrl+C Quit
Ctrl+P Refresh project list from Posit Connect
Ctrl+U Safe-merge sync vault → all projects (shows confirmation)

Navigation

Key Action
j / ↓ Move down
k / ↑ Move up
h / ← / Esc Return to sidebar
l / → / Enter Enter content pane (from sidebar)
g Jump to top
G Jump to bottom
f / / Open fuzzy filter
F Clear filter

Projects page

Key Action
Enter / Space Expand / collapse project to show its env vars
x On a project row: toggle project in/out of sync whitelist. On a var row: toggle var exclusion for that project
a Add an env var to the selected project (fuzzy-picks from vault keys)
d Delete the selected env var from the project

Env Vars page

Key Action
Enter / Space Open popup showing which projects use the selected var
e / E Open the selected var's vault value in $EDITOR

Vault page

Key Action
n New entry (opens key field for editing)
e / Enter Edit value of selected entry
E Open value in $EDITOR
d / Delete Delete selected entry

Settings page

Key Action
e / Enter Edit selected field (theme field cycles values instead)
Esc Cancel edit

Safe-merge sync

Ctrl+U iterates every non-blacklisted content item and, for each one:

  1. Fetches current env vars from the Connect API
  2. Overlays vault values only for keys that already exist in the project
  3. PATCHes the merged set back

It never adds new environment variables to a project that doesn't already define them, and never deletes existing ones. Safe to run repeatedly.

License

MIT

Metadata

Release files for posit-connect-secrets-manager 0.5.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for posit-connect-secrets-manager 0.5.1
File Size Uploaded
posit_connect_secrets_manager-0.5.1.tar.gz 55.3 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for posit-connect-secrets-manager 0.5.1
File
posit_connect_secrets_manager-0.5.1-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
posit_connect_secrets_manager-0.5.1-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
posit_connect_secrets_manager-0.5.1-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 11.4 MB

Release files / posit_connect_secrets_manager-0.5.1.tar.gz

Download URL posit_connect_secrets_manager-0.5.1.tar.gz
Size 55.3 kB
Tags Source
SHA-256 checksum
How to use checksums
4465ba51b4620bf8c84a623d93f66441abd8cc3a88dacec580b445f6cfe0d13f
BLAKE2b-256 checksum
How to use checksums
e39a2c6f20cac5a124022f6c47b2731ed355885501cfb7387dab89126ace6252
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.

Transparency log

Release files / posit_connect_secrets_manager-0.5.1-py3-none-win_amd64.whl

Download URL posit_connect_secrets_manager-0.5.1-py3-none-win_amd64.whl
Size 2.2 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
1d3bd511dabcc460ad7449150a63e416774017708710e8dd4b57268ddfbb4221
BLAKE2b-256 checksum
How to use checksums
420f8b5190664857d7ca5c7791302caa3af92205e362335d26e8ec390d7f4968
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.

Transparency log

Release files / posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 2.4 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
e2c21bb73c60f24564e87f51bb0e8e98e4bb76cb3c633550619fe2bb474cb20f
BLAKE2b-256 checksum
How to use checksums
d96bde0d505b28750960856d050f5c23bb61e7ea9c46079a08a107f3b9a352c6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.

Transparency log

Release files / posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL posit_connect_secrets_manager-0.5.1-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 2.2 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
06f0667b8317b6c4d2fb9e7e3d2c286143ed56cce54f553b5ccfacb595d4f547
BLAKE2b-256 checksum
How to use checksums
6eb763c33e96416068403f3e840c89d7ff794c1206562ae336726e5f6d4aaf4f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.

Transparency log

Release files / posit_connect_secrets_manager-0.5.1-py3-none-macosx_11_0_arm64.whl

Download URL posit_connect_secrets_manager-0.5.1-py3-none-macosx_11_0_arm64.whl
Size 2.2 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
e871be995a372aceff673b30f13e076e40c3f2a192c59fc668c2b42b99c3848f
BLAKE2b-256 checksum
How to use checksums
2951197f83a3aed4c6ccd06395c91a46d95dc8db4158a714f971b48d4dafe4ca
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.

Transparency log

Release files / posit_connect_secrets_manager-0.5.1-py3-none-macosx_10_12_x86_64.whl

Download URL posit_connect_secrets_manager-0.5.1-py3-none-macosx_10_12_x86_64.whl
Size 2.3 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
86edc7e4f2378366a25b499d8b80dca015862f2bc17b20c2432bbb6a451d1bcf
BLAKE2b-256 checksum
How to use checksums
5570a2f3b6e262c6b97b1465eb919d8e4540a6dde91ee990a9b4d366ddca3b4c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 20, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.5.1 This release

6 release files

0.5.0

6 release files

0.4.1

6 release files

0.4.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page