Skip to content

kindgi env

Manage per-environment values that resolve into needs.env at deploy time.

List resolved env values for the target env (merges config + .env.<envName>).

Terminal window
kindgi env list [--env <name>] [--reveal] [--force-reveal] [--path <dir>]

Flags:

  • --env <value>: The environment: local is the project's own env files, any other name its .env.&lt;name&gt;. Default: staging.
  • --force-reveal: With --reveal, print the values even when stdout isn't a terminal (a file, a pipe, CI).
  • --path <value>: The pack root, where the env files are. Default: the current directory.
  • --reveal: Print the values instead of redacting them. Refused when stdout isn't a terminal (a file, a pipe), unless --force-reveal is also given.

Set a KEY=VALUE in .env.<envName>. Refuses to overwrite unless --force.

Terminal window
kindgi env set <KEY> <VALUE> [--env <name>] [--force] [--path <dir>]

Flags:

  • --env <value>: The environment: local is the project's own env files, any other name its .env.&lt;name&gt;. Default: staging.
  • --force: Change a key an env file already sets: overwrite it, or override a lower-precedence file. By default set refuses.
  • --path <value>: The pack root, where the env files are. Default: the current directory.

Remove KEY from .env.<envName>. Idempotent — no error if the key is absent.

Terminal window
kindgi env unset <KEY> [--env <name>] [--path <dir>]

Flags:

  • --env <value>: The environment: local is the project's own env files, any other name its .env.&lt;name&gt;. Default: staging.
  • --path <value>: The pack root, where the env files are. Default: the current directory.

Fetch remote env values via /v1/env/* and merge into .env.<envName>. Requires --scope.

Terminal window
kindgi env pull [--env <name>] --scope=<kind>[:id] [--path <dir>] [--overwrite-existing]

Flags:

  • --env <value>: The environment to pull, written to its .env.&lt;name&gt; (local: the project's own env files). Default: staging.
  • --overwrite-existing: Replace keys an env file already sets. By default they are skipped.
  • --path <value>: The pack root, where the env files are. Default: the current directory.
  • --scope <value>: Whose values to pull: tenant, org:&lt;orgId&gt; or project:&lt;projectId&gt;. Required.

Scaffold .env.example for a deployment target. Interactive prompt when flags omit an axis and stdin is a TTY.

Terminal window
kindgi env init [--secrets-backend=<none|postgres|secret-manager>] [--kms=<gcp|aws|libsodium|vault>] [--out=<path>] [--force] [--non-interactive]

Flags:

  • --force: Overwrite an existing file at the output path. By default init refuses.
  • --kms <value>: The KMS for the postgres or secret-manager backend: gcp, aws, libsodium or vault. Asked for when needed and omitted.
  • --non-interactive: Never prompt: fail when --secrets-backend, or a needed --kms, is missing.
  • --out <value>: Where to write the file. Default: .env.example in the current directory.
  • --secrets-backend <value>: The deployment's secrets backend: none, postgres or secret-manager. Asked for when omitted on a terminal.

Show the process env a deployed pack service gets in --env: each name the pack declares (env.required / env.optional) and its value or Secret Manager reference from environments.<name>.env. Prints Terraform input (default) or gcloud flags; exits 1 when a required name has no value or a secret is given in the clear.

Terminal window
kindgi env plan [--env <name>] [--format=terraform|gcloud] [--path <dir>]

Flags:

  • --env <value>: The environment to plan, from environments.&lt;name&gt;.env in kindgi.config.ts. Default: staging.
  • --format <value>: The output: terraform (default) for Terraform input, or gcloud for --set-env-vars / --set-secrets flags.
  • --path <value>: The pack root, where kindgi.config.ts is. Default: the current directory.

Every command also takes the global flags.