Skip to main content

env-sync Viewer

Know the moment your fleet drifts, or goes quiet. One dashboard for secrets-drift status across every service, env, and platform.

Why this exists

env-sync keeps 1Password and your deploy platforms in agreement. But is it actually running? A sync job that quietly died a month ago looks exactly like a healthy fleet on a dashboard that only counts problems: “0 issues.” env-sync Viewer collects drift status for every service, env, and target on a schedule, keeps the history, and treats not hearing back as a problem too.

Silence shows up as stale

Every target that has not reported a healthy result within the staleness window (default 26 h) is flagged stale. It never just disappears. A dead collector turns the whole board stale, not empty.

Least privilege, enforced by Postgres

The collector can only INSERT, and the viewer can only SELECT. Every other role is revoked, with FORCE ROW LEVEL SECURITY on top. This is proven by a test suite against a real Postgres, not by mocks.

Fingerprints never leave the server

Drift is computed server-side. The browser gets match/drift/missing, never a fingerprint. Access needs a confirmed sign-in and an explicit allowlist.

Survives the Go cutover

The collector shells out to the env-sync CLI's versioned JSON contract and never imports its internals. When env-sync moves from TypeScript to Go, the collector keeps working unchanged.

Quickstart

git clone https://github.com/catesworks/env-sync-viewer.git
cd env-sync-viewer && pnpm install && pnpm build

# schema + INSERT-only / SELECT-only roles, with RLS
DATABASE_URL=<admin-url> pnpm db:deploy

# one collector pass over your inventory (needs env-sync on PATH)
DATABASE_URL=<collector-login-url> node apps/collector/dist/main.js inventory.json

# the dashboard (Supabase Auth + VIEWER_ALLOWLIST)
pnpm --filter @env-sync-viewer/web dev

Full walkthrough, including a no-credential smoke run: Getting started.

Where it stands

This is an internal tool with no public deployment yet. It has been security-reviewed by an adversarial pass that caught two real bugs, both fixed before it shipped. It is tested against real Postgres 16, with fakes standing in for env-sync and Supabase Auth. It has not yet run against a live Supabase project or real platform credentials.