What is env-sync Viewer?
env-sync Viewer is a fleet-wide secrets-drift dashboard for
env-sync, the CLI that keeps 1Password (the source of
truth) in sync with the platforms services actually run on: Vercel, Render, AWS SSM, GitHub
Actions, CapRover, and local dotenv files. env-sync diff tells you whether one service in one
env has drifted, right now, on your machine. env-sync Viewer shows you the whole fleet at once, over
time, and flags when you stop hearing from a target.
It has three parts:
apps/collector: a scheduled job that runs the installedenv-syncbinary (env-sync diff --format json) for every manifest, env, and service in its inventory. It writes each run's results to Postgres in one transaction.packages/db: the Drizzle schema (env_sync.collector_runs,drift_snapshots,drift_snapshot_keys) plus hand-written SQL that locks those tables behind two single-purpose Postgres roles and row-level security.apps/web: a read-only Next.js dashboard. It shows every target's latest status, a per-target stale flag, and the last 20 collector runs. You must sign in (Supabase Auth) and be on an explicit allowlist. Secret fingerprints never reach the browser.
:::note Current status
This is a private, internal tool. No deployment is published yet, and it has not been run
against a real Supabase project or real platform credentials. What it has been tested against:
real throwaway Postgres 16 containers (26 row-level-security tests, including a regression that
proves the suite is not deny-only), a fake env-sync binary for the collector, and a fake Supabase
auth layer for the viewer. It also passed a final adversarial review. That review found two real
bugs, and both were fixed before this tool was ever deployed (see
Architecture).
:::
Next: Getting started runs the whole stack locally.