Core workflow
Environment & security
Manage encrypted per-app configuration with version-aware restore semantics.
Environment commands
phelix env manages per-app secrets. Each subcommand prompts for the app and key when run without arguments (in a TTY).
phelix env set MyApp DATABASE_URL=postgresql://localhost/dbphelix env get MyApp DATABASE_URL # sensitive values are maskedphelix env list MyApp # values shown as ***REDACTED***phelix env unset MyApp DATABASE_URLphelix env check MyApp DATABASE_URL # exit-status friendly existence checkEncryption model
Values are encrypted at rest with AES-256-GCM. The encryption key lives at ~/.phelix/master.key (auto-generated, 0600 permissions). Registry credentials use the same encrypted storage mechanism and are never logged in plaintext.
env check is exit-status friendly - ideal for gates in build scripts and health probes.
Injection and snapshots
Encrypted values are injected into the app process at start, and snapshotted alongside each versioned build (env/vN.enc) so a rollback restores the matching env - never a binary without its configuration.