envdrift vault-push¶
Push encryption keys from local .env.keys files to cloud vaults.
This command is specific to dotenvx keys; SOPS users should use their SOPS key management workflows.
Synopsis¶
Description¶
The vault-push command uploads DOTENV_PRIVATE_KEY_* secrets from local .env.keys files to cloud vaults.
This is the reverse of envdrift sync - it pushes local keys to the vault instead of pulling from it.
This enables secure key distribution by:
- Uploading newly generated encryption keys to centralized vault storage
- Sharing keys across team members and CI/CD pipelines
- Backing up encryption keys to secure cloud storage
Supported vault providers:
- Azure Key Vault - Microsoft Azure's secret management service
- AWS Secrets Manager - Amazon Web Services secret storage
- HashiCorp Vault - Open-source secrets management
- Google Secret Manager (GCP) - Google Cloud's secret management service
Modes¶
Normal Mode (from .env.keys)¶
Reads a specific key from a .env.keys file and pushes it to the vault.
This reads DOTENV_PRIVATE_KEY_PRODUCTION from ./services/myapp/.env.keys and pushes it to the vault as my-secret-name.
Direct Mode¶
Push a key-value pair directly without reading from a file.
All Services Mode¶
Push all secrets defined in the sync configuration. This mode automatically checks for unencrypted files (encrypting them if needed) and pushes keys for any secrets that are missing from the vault.
Without --profile, --all processes only untagged mappings. Add a profile to process regular mappings plus the exact matching profile while skipping
other profile-tagged mappings:
If a sync mapping sets env_file, --all encrypts that custom dotenv filename
and still pushes the canonical key named by environment:
[[vault.sync.mappings]]
secret_name = "postgres-key"
folder_path = "secrets/postgresql"
environment = "production"
env_file = "postgresql.env"
To overwrite existing secrets instead of skipping them, add --force:
When the local files are already encrypted, add --skip-encrypt to bypass the encryption step and only push keys:
Options¶
FOLDER¶
Path to the folder containing the .env.keys file (normal mode) or the secret name (direct mode).
SECRET_NAME¶
Name for the secret in the vault (normal mode) or the value to push (direct mode).
--env, -e¶
Environment suffix for the key name. Required in normal mode.
For example, --env soak looks for DOTENV_PRIVATE_KEY_SOAK in the .env.keys file.
--direct¶
Enable direct mode. Push a key-value pair directly without reading from a file.
--all¶
Push all secrets defined in sync config (skipping existing unless --force is set).
--profile¶
In --all mode, process regular (untagged) mappings plus mappings tagged with the selected profile. Mappings tagged with other profiles are skipped.
Without --profile, only regular mappings are processed. An empty selection exits with code 1. Using --profile without --all prints a warning and
leaves single-service or direct mode unchanged.
--force, -f¶
Push all secrets in --all mode even if they already exist.
--skip-encrypt¶
Skip the encryption step in --all mode and only push keys to the vault (use when files are already encrypted).
Using it without --all prints a warning and is ignored.
--config, -c¶
Path to sync config file (TOML).
--provider, -p¶
Vault provider to use. Required unless configured in envdrift.toml.
Options: azure, aws, hashicorp, gcp
--vault-url¶
Vault URL. Required for Azure and HashiCorp unless configured in envdrift.toml
(for HashiCorp, the standard VAULT_ADDR environment variable is also honored as a
fallback). Azure vault URLs must start with https://.
--region¶
AWS region for Secrets Manager. Default: us-east-1.
--project-id¶
GCP project ID for Secret Manager. Required for the gcp provider unless configured in envdrift.toml.
Configuration¶
Settings can be configured in envdrift.toml:
[vault]
provider = "azure"
[vault.azure]
vault_url = "https://my-keyvault.vault.azure.net/"
[vault.aws]
region = "us-east-1"
[vault.hashicorp]
url = "https://vault.example.com:8200"
[vault.gcp]
project_id = "my-gcp-project"
When configured, you can omit the --provider, --vault-url, and --project-id flags.
Examples¶
Azure Key Vault¶
# Push from .env.keys file
envdrift vault-push ./services/myapp myapp-key --env production \
-p azure --vault-url https://myvault.vault.azure.net/
# Using config from envdrift.toml
envdrift vault-push ./services/myapp myapp-key --env production
AWS Secrets Manager¶
# Push from .env.keys file
envdrift vault-push ./services/myapp myapp-key --env staging -p aws
# With custom region
envdrift vault-push ./services/myapp myapp-key --env staging \
-p aws --region us-west-2
# Direct mode
envdrift vault-push --direct myapp-staging-key \
"DOTENV_PRIVATE_KEY_STAGING=abc123..." -p aws
HashiCorp Vault¶
# Push from .env.keys file
envdrift vault-push ./services/myapp myapp-key --env dev \
-p hashicorp --vault-url https://vault.example.com:8200
CI/CD Integration¶
GitHub Actions¶
jobs:
push-keys:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Azure Login
uses: azure/login@v1
with:
creds: ${{ secrets.AZURE_CREDENTIALS }}
- name: Push encryption key to vault
run: |
pip install envdrift[azure]
envdrift vault-push ./services/myapp myapp-key --env production
Output¶
On success:
On error:
Exit Codes¶
| Code | Meaning |
|---|---|
| 0 | Success (secret pushed; in --all mode, every mapping pushed or skipped cleanly) |
| 1 | Error (auth failure, file not found, vault error, or any --all mapping failure) |
| 1 | --all: a mapping's folder_path does not exist (broken sync config) |
| 1 | --all: the selected profile contains no regular or matching mappings |
Authentication¶
Azure Key Vault¶
Uses Azure Identity's DefaultAzureCredential:
- Environment variables (
AZURE_CLIENT_ID,AZURE_TENANT_ID,AZURE_CLIENT_SECRET) - Managed Identity (in Azure)
- Azure CLI (
az login)
AWS Secrets Manager¶
Uses boto3's credential chain:
- Environment variables (
AWS_ACCESS_KEY_ID,AWS_SECRET_ACCESS_KEY) - Shared credential file (
~/.aws/credentials) - IAM role (EC2, ECS, Lambda)
HashiCorp Vault¶
VAULT_TOKENenvironment variable
Security Notes¶
- Ensure you have write permissions to the vault
- The secret value includes the full
KEY=valueformat for compatibility with dotenvx - Use CI/CD secrets or managed identities for authentication in production
See Also¶
- vault-pull - Config-free single-secret pull (opposite of vault-push)
- sync - Pull encryption keys from vaults to local files
- pull - Config-based, multi-service pull + decrypt
- encrypt - Check/perform encryption
- Env File Sync Guide - Detailed vault setup guide