tesserakit-config
Inventory a project's configuration, check for leaked secrets, and report config drift.
tessera-config scans env files and source code, aggregates every configuration key, redacts secret values at load time, and reports the gaps between what is documented, what is set, and what is actually used. No code is executed and no network calls are made.
What it scans
- Real env files (
.env,.env.local, ...) → keys and (redacted) values. - Example files (
.env.example,.env.sample,.env.template) → documented keys. - Source code (
.py,.js,.ts,.rb,.go, ...) → env-var references:os.getenv("X"),os.environ["X"],os.environ.get("X"),getenv("X"),process.env.X,process.env["X"].
Secret safety
Values for secret-named keys (*TOKEN*, *SECRET*, *PASSWORD*, *API_KEY*,
*CREDENTIAL*, ...) are masked before any record or artifact is written. The
inventory shows (set) for non-secret values and a masked preview for secret
ones; the raw value never leaves the source file.
Audit a project
tessera config audit --input . --output ./out/config_pack
Artifacts written:
config_inventory.jsonl one ConfigKey per key (env/example/code flags, masked value)
index.md the inventory table
validation_report.md findings (leaked secrets, drift)
coverage_report.md documented %, used %, secret count
drift_report.md used-but-undocumented / set-but-undocumented / documented-but-unused
Validation rules
possible_committed_secret— a secret-named key has a value in a real.envsecret_value_in_nonsecret_key— a value shaped like a secret (e.g.MY_THING=ghp_…) under a key whose name isn't secret-like; name-based detection alone would miss itmissing_in_example— used in code but not documented in any.env.exampleundocumented_env_key— set in.envbut not in any exampleunused_documented_key— documented in an example but never used or setno_config_keys— nothing found
Secret detection screens values by shape (AWS/GitHub/Slack/Stripe/JWT/etc. + a conservative high-entropy heuristic) in addition to key names, with UUIDs excluded.
Metadata
Release files for tesserakit-config 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| tesserakit_config-0.4.0.tar.gz | 9.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| tesserakit_config-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 21.1 kB
Release files / tesserakit_config-0.4.0.tar.gz
| Download URL | tesserakit_config-0.4.0.tar.gz |
|---|---|
| Size | 9.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
70a547fbc3503f053463001abbff9303c54ee28d520f08af44e5e8aa8b0734e6
|
|
BLAKE2b-256 checksum How to use checksums |
9a18c29810b98ca86d610e55008aaf67251cc5be4a18376eebb8710eaa46f8a3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.11
|
Release files / tesserakit_config-0.4.0-py3-none-any.whl
| Download URL | tesserakit_config-0.4.0-py3-none-any.whl |
|---|---|
| Size | 11.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1535e2565266e4dc5ab7aab0479a586050f55f179f991637f6623350f6afcaee
|
|
BLAKE2b-256 checksum How to use checksums |
3565402d9fd7d6858d6ee0291e75170119427461291cb865eac3dc7cd28f8940
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.11
|