Skip to content

Command Palette

Search for a command to run...

Core workflow

Environment & security

Manage encrypted per-app configuration with version-aware restore semantics.

Environment commands

phelix env manages per-app secrets. Each subcommand prompts for the app and key when run without arguments (in a TTY).

Terminal
phelix env set    MyApp DATABASE_URL=postgresql://localhost/dbphelix env get    MyApp DATABASE_URL      # sensitive values are maskedphelix env list   MyApp                   # values shown as ***REDACTED***phelix env unset  MyApp DATABASE_URLphelix env check  MyApp DATABASE_URL      # exit-status friendly existence check

Encryption model

Values are encrypted at rest with AES-256-GCM. The encryption key lives at ~/.phelix/master.key (auto-generated, 0600 permissions). Registry credentials use the same encrypted storage mechanism and are never logged in plaintext.

env check is exit-status friendly - ideal for gates in build scripts and health probes.

Injection and snapshots

Encrypted values are injected into the app process at start, and snapshotted alongside each versioned build (env/vN.enc) so a rollback restores the matching env - never a binary without its configuration.

Secret masking