Skip to main content

tesserakit-config

Inventory a project's configuration, check for leaked secrets, and report config drift.

tessera-config scans env files and source code, aggregates every configuration key, redacts secret values at load time, and reports the gaps between what is documented, what is set, and what is actually used. No code is executed and no network calls are made.

What it scans

  • Real env files (.env, .env.local, ...) → keys and (redacted) values.
  • Example files (.env.example, .env.sample, .env.template) → documented keys.
  • Source code (.py, .js, .ts, .rb, .go, ...) → env-var references: os.getenv("X"), os.environ["X"], os.environ.get("X"), getenv("X"), process.env.X, process.env["X"].

Secret safety

Values for secret-named keys (*TOKEN*, *SECRET*, *PASSWORD*, *API_KEY*, *CREDENTIAL*, ...) are masked before any record or artifact is written. The inventory shows (set) for non-secret values and a masked preview for secret ones; the raw value never leaves the source file.

Audit a project

tessera config audit --input . --output ./out/config_pack

Artifacts written:

config_inventory.jsonl   one ConfigKey per key (env/example/code flags, masked value)
index.md                 the inventory table
validation_report.md     findings (leaked secrets, drift)
coverage_report.md       documented %, used %, secret count
drift_report.md          used-but-undocumented / set-but-undocumented / documented-but-unused

Validation rules

  • possible_committed_secret — a secret-named key has a value in a real .env
  • secret_value_in_nonsecret_key — a value shaped like a secret (e.g. MY_THING=ghp_…) under a key whose name isn't secret-like; name-based detection alone would miss it
  • missing_in_example — used in code but not documented in any .env.example
  • undocumented_env_key — set in .env but not in any example
  • unused_documented_key — documented in an example but never used or set
  • no_config_keys — nothing found

Secret detection screens values by shape (AWS/GitHub/Slack/Stripe/JWT/etc. + a conservative high-entropy heuristic) in addition to key names, with UUIDs excluded.

Metadata

Release files for tesserakit-config 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tesserakit-config 0.4.0
File Size Uploaded
tesserakit_config-0.4.0.tar.gz 9.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tesserakit-config 0.4.0
File Interpreter ABI Platform
tesserakit_config-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 21.1 kB

Release files / tesserakit_config-0.4.0.tar.gz

Download URL tesserakit_config-0.4.0.tar.gz
Size 9.3 kB
Tags Source
SHA-256 checksum
How to use checksums
70a547fbc3503f053463001abbff9303c54ee28d520f08af44e5e8aa8b0734e6
BLAKE2b-256 checksum
How to use checksums
9a18c29810b98ca86d610e55008aaf67251cc5be4a18376eebb8710eaa46f8a3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.11

Release files / tesserakit_config-0.4.0-py3-none-any.whl

Download URL tesserakit_config-0.4.0-py3-none-any.whl
Size 11.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1535e2565266e4dc5ab7aab0479a586050f55f179f991637f6623350f6afcaee
BLAKE2b-256 checksum
How to use checksums
3565402d9fd7d6858d6ee0291e75170119427461291cb865eac3dc7cd28f8940
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.11

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

0.3.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page