pr0h0
Developer Tools

SafeEnv

A self-hosted encrypted environment-variable manager for teams, with a Go dashboard, CLI and runtime SDKs.

Environment variables and secrets tend to spread across .env files, chat messages and CI settings. Nobody knows which copy is current, who changed what, or which machine still has an old key.

SafeEnv gives teams one place to manage them. Values are encrypted with AES-256-GCM envelope encryption, access is controlled through roles and machine identities, and every change is audited. Applications fetch their configuration at startup through a Go CLI or runtime SDKs instead of shipping secrets inside images or repositories.

It is self-hosted, so the secrets never leave infrastructure the team controls. The dashboard and API are written in Go with server-rendered templ pages over PostgreSQL, and the service that answers runtime requests scales separately from the dashboard.

Key features

  • AES-256-GCM envelope encryption for stored values
  • Roles, permissions and machine identities
  • Audit logs
  • Go CLI and runtime SDKs
  • Runtime pull traffic served by a separately scalable service