fnox - Gone are the days of .env
(1) By chooky on 2026-09-15 03:17:58 [link] [source]
I came across this a couple days ago. Seems like a way of integrating project secrets without the need for a .env file. I might give it a go for the next project that needs secrets. https://fnox.jdx.dev/
(2) By joshuablais on 2026-09-15 11:56:33 in reply to 1 [source]
I have been using .envrc for development for some time, combined with direnv in emacs. You setup the dependencies for the project, as soon as you 'cd' into the repo, the environment builds itself and you are good to go. This is one of the huge benefits of nix/guix in that these environments then expand out to all things you possibly could need to build a project at whatever version you want. For secrets, I actually just call 'pass' and store all secrets gpg encrypted.
(3) By cashmere on 2026-09-15 20:14:42 in reply to 2 [link] [source]
I can see the value in non-Nix/Guix environments or in working with other corporates.
As an example, my GPG identity is very tied to my machines and workflow. I sign commits, use it for authentication, privilege escalation, password-store management, my Nitrokey is basically just a GPG card (I don't even use the WebAuthn/FIDO features) and maybe some other little things I forgot to mention.
I'm very attached to this setup, and every time I have to use a new machine without it I start to hate myself for being so dependent on GPG. Added to that, it's not as easy to set up as just enabling some services and being good to go.
While I don't have a reason yet to use it, I see why it can be very appealing for secrets management, especially as they support age for encryption, which is really easy to use.