Skip to main content

What is env-sync Viewer?

env-sync Viewer is a fleet-wide secrets-drift dashboard for env-sync, the CLI that keeps 1Password (the source of truth) in sync with the platforms services actually run on: Vercel, Render, AWS SSM, GitHub Actions, CapRover, and local dotenv files. env-sync diff tells you whether one service in one env has drifted, right now, on your machine. env-sync Viewer shows you the whole fleet at once, over time, and flags when you stop hearing from a target.

It has three parts:

  • apps/collector: a scheduled job that runs the installed env-sync binary (env-sync diff --format json) for every manifest, env, and service in its inventory. It writes each run's results to Postgres in one transaction.
  • packages/db: the Drizzle schema (env_sync.collector_runs, drift_snapshots, drift_snapshot_keys) plus hand-written SQL that locks those tables behind two single-purpose Postgres roles and row-level security.
  • apps/web: a read-only Next.js dashboard. It shows every target's latest status, a per-target stale flag, and the last 20 collector runs. You must sign in (Supabase Auth) and be on an explicit allowlist. Secret fingerprints never reach the browser.

:::note Current status

This is a private, internal tool. No deployment is published yet, and it has not been run against a real Supabase project or real platform credentials. What it has been tested against: real throwaway Postgres 16 containers (26 row-level-security tests, including a regression that proves the suite is not deny-only), a fake env-sync binary for the collector, and a fake Supabase auth layer for the viewer. It also passed a final adversarial review. That review found two real bugs, and both were fixed before this tool was ever deployed (see Architecture).

:::

Next: Getting started runs the whole stack locally.