← all projects

open-envault.

Local-first, SOPS-compatible secrets for Git and Rust

why it matters

open-envault is an open-source, Rust-first secrets tool for Git workflows. Encrypted profiles (open-envault.yaml, config/env.schema.yaml, secrets/*.enc) live in Git alongside public age recipients, while private keys stay local via env vars, key files, or ~/.config/open-envault/keys. The oenv CLI (init, setup, check, exec, diff, rotate, import) is fail-closed with redacted diagnostics and zeroized memory-only secrets, and encrypted files are plain SOPS age files that sops can decrypt and vice versa. A thin npm wrapper exposes exec/check for Node and NestJS, and a Rust library supports Arqen services; prebuilt binaries ship with every GitHub Release.

what shipped

  • ◆SOPS 3.13 age byte-compatible encryption with no sops/rage needed at runtime
  • ◆Git-native layout: ciphertext and recipients in Git, private keys never leave your machines
  • ◆Fail-closed CLI with redacted diagnostics, schema validation, and zeroized memory-only secrets
  • ◆oenv exec runtime injection plus TypeScript and Rust APIs for Node, NestJS, and Arqen