Env & Secrets Manager
Complete environment variable and secrets management lifecycle: .env file structure across dev/staging/production, .env.example auto-generation that strips sensitive values, required-variable validation at startup, secret leak detection in git history, credential rotation playbooks, environment drift detection, and integration with HashiCorp Vault, AWS SSM, 1Password CLI, and Doppler.
Core Capabilities
- .env lifecycle — structured layout with categorized sections, auto-generated
.env.example (strips secrets), environment-specific files, and fail-fast startup validation.
- Secret leak detection — regex scan of git history, working tree, and staged files; pre-commit hooks; patterns for API keys, tokens, passwords, private keys.
- Credential rotation — per-secret playbooks, scope analysis, zero-downtime dual-read rotation, post-rotation verification and monitoring.
- Secret manager integration — HashiCorp Vault (KV v2 + OIDC), AWS SSM Parameter Store (KMS), 1Password CLI (template injection), Doppler (project/config).
- Drift detection — compare variable key sets between staging and production and report missing/extra keys.
When to Use
- Setting up a new project — scaffold .env.example and validation.
- Before every commit — scan for accidentally staged secrets.
- Post-incident — rotate leaked credentials systematically.
- Onboarding developers — provide complete environment setup.
- Auditing — detect environment drift between staging and production.
- Compliance — demonstrate secret management practices.
Clarify First
Before running, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
Tools
| Tool |
Purpose |
Command |
env_validator.py |
Validate a .env against .env.example: missing/extra vars, empty secrets, leaked credentials |
python scripts/env_validator.py .env.example .env --strict --check-secrets |
secret_scanner.py |
Scan a directory/file for hardcoded secrets via pattern matching |
python scripts/secret_scanner.py ./src --severity high --json |
env_sync_checker.py |
Compare env configs across dev/staging/prod and report drift |
python scripts/env_sync_checker.py .env.* --baseline .env.example |
References
Load the reference that matches the task — keep this file lean and pull detail on demand:
- references/env-file-structure.md — canonical
.env layout, the .env.* file hierarchy, required .gitignore patterns, and the full Python startup-validation script. Read when scaffolding a project or wiring validation.
- references/leak-detection-and-rotation.md — the git-history secret scanner, pre-commit hook, the 4-step credential rotation playbook (scope, generate, dual-write, verify), and the environment-drift detection script. Read when scanning for leaks or rotating credentials.
- references/secret-manager-integration.md — concrete Vault, AWS SSM, and Doppler commands for storing, reading, and rotating secrets. Read when integrating a secret manager.
- references/best-practices-and-troubleshooting.md — common pitfalls, the 8 best practices, the troubleshooting table, and the success-criteria bar. Read when reviewing a setup or debugging.
Scope & Limitations
This skill covers:
.env file scaffolding, hierarchy, and validation for any language/framework
- Secret leak detection in git history, staged files, and working tree
- Credential rotation playbooks with zero-downtime dual-read strategy
- Integration patterns for HashiCorp Vault, AWS SSM, 1Password CLI, and Doppler
This skill does NOT cover:
- Runtime secret injection in Kubernetes (see
engineering/ci-cd-pipeline-builder for deployment pipeline secrets)
- Infrastructure-as-code for provisioning Vault clusters or SSM policies (see
engineering/ci-cd-pipeline-builder)
- Application-level encryption at rest or in transit (see
engineering/api-design-reviewer for API security patterns)
- Identity and access management (IAM) role design or SSO/OIDC provider configuration (see
ra-qm-team/ compliance skills for access control frameworks)
Integration Points
| Skill |
Integration |
Data Flow |
engineering/ci-cd-pipeline-builder |
Inject secrets from Vault/SSM/Doppler into CI/CD pipeline stages |
Rotation playbook outputs feed pipeline secret-update steps |
engineering/dependency-auditor |
Flag dependencies that bundle or require hardcoded credentials |
Dependency audit findings trigger secret leak scans on affected repos |
engineering/skill-security-auditor |
Validate that no skill packages ship embedded secrets or credentials |
Security audit references this skill's regex patterns for detection |
engineering/codebase-onboarding |
Include .env.example setup and secret-manager access in onboarding checklists |
Onboarding workflow consumes the .env hierarchy and validation script |
engineering/observability-designer |
Monitor authentication failures post-rotation; alert on anomalous secret access |
Post-rotation verification metrics flow into observability dashboards |
ra-qm-team/soc2-compliance-auditor |
Demonstrate secret management controls for SOC 2 CC6.1 and CC6.6 criteria |
Rotation audit logs and access policies serve as SOC 2 evidence artifacts |
1---2name: env-secrets-manager3description: Environment and secrets management lifecycle: .env scaffolding, validation, leak detection, and rotation across Vault, AWS SSM, 1Password, and Doppler. Use when setting up projects, scanning for leaked secrets, or rotating credentials.4license: MIT + Commons Clause5---6# Env & Secrets Manager
7
8Complete environment variable and secrets management lifecycle: .env file structure across dev/staging/production, .env.example auto-generation that strips sensitive values, required-variable validation at startup, secret leak detection in git history, credential rotation playbooks, environment drift detection, and integration with HashiCorp Vault, AWS SSM, 1Password CLI, and Doppler.
9
10## Core Capabilities
11
12- **.env lifecycle** — structured layout with categorized sections, auto-generated `.env.example` (strips secrets), environment-specific files, and fail-fast startup validation.
13- **Secret leak detection** — regex scan of git history, working tree, and staged files; pre-commit hooks; patterns for API keys, tokens, passwords, private keys.
14- **Credential rotation** — per-secret playbooks, scope analysis, zero-downtime dual-read rotation, post-rotation verification and monitoring.
15- **Secret manager integration** — HashiCorp Vault (KV v2 + OIDC), AWS SSM Parameter Store (KMS), 1Password CLI (template injection), Doppler (project/config).
16- **Drift detection** — compare variable key sets between staging and production and report missing/extra keys.
17
18## When to Use
19
20- Setting up a new project — scaffold .env.example and validation.
21- Before every commit — scan for accidentally staged secrets.
22- Post-incident — rotate leaked credentials systematically.
23- Onboarding developers — provide complete environment setup.
24- Auditing — detect environment drift between staging and production.
25- Compliance — demonstrate secret management practices.
26
27## Clarify First
28
29Before running, confirm these inputs. If any is unknown or vague, ASK — do not assume:
30
31- [ ] **Task** — scaffold/validate a `.env`, scan for leaked secrets, or check env drift (selects `env_validator.py` vs `secret_scanner.py` vs `env_sync_checker.py`)
32- [ ] **Target paths** — the `.env`/`.env.example` files or directory to scan (the input the tools read)
33- [ ] **Secret manager** — Vault, AWS SSM, 1Password, or Doppler (determines the integration and rotation commands generated)
34
35Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
36
37## Tools
38
39| Tool | Purpose | Command |
40|------|---------|---------|
41| `env_validator.py` | Validate a `.env` against `.env.example`: missing/extra vars, empty secrets, leaked credentials | `python scripts/env_validator.py .env.example .env --strict --check-secrets` |
42| `secret_scanner.py` | Scan a directory/file for hardcoded secrets via pattern matching | `python scripts/secret_scanner.py ./src --severity high --json` |
43| `env_sync_checker.py` | Compare env configs across dev/staging/prod and report drift | `python scripts/env_sync_checker.py .env.* --baseline .env.example` |
44
45## References
46
47Load the reference that matches the task — keep this file lean and pull detail on demand:
48
49- **[references/env-file-structure.md](references/env-file-structure.md)** — canonical `.env` layout, the `.env.*` file hierarchy, required `.gitignore` patterns, and the full Python startup-validation script. Read when scaffolding a project or wiring validation.
50- **[references/leak-detection-and-rotation.md](references/leak-detection-and-rotation.md)** — the git-history secret scanner, pre-commit hook, the 4-step credential rotation playbook (scope, generate, dual-write, verify), and the environment-drift detection script. Read when scanning for leaks or rotating credentials.
51- **[references/secret-manager-integration.md](references/secret-manager-integration.md)** — concrete Vault, AWS SSM, and Doppler commands for storing, reading, and rotating secrets. Read when integrating a secret manager.
52- **[references/best-practices-and-troubleshooting.md](references/best-practices-and-troubleshooting.md)** — common pitfalls, the 8 best practices, the troubleshooting table, and the success-criteria bar. Read when reviewing a setup or debugging.
53
54## Scope & Limitations
55
56**This skill covers:**
57- `.env` file scaffolding, hierarchy, and validation for any language/framework
58- Secret leak detection in git history, staged files, and working tree
59- Credential rotation playbooks with zero-downtime dual-read strategy
60- Integration patterns for HashiCorp Vault, AWS SSM, 1Password CLI, and Doppler
61
62**This skill does NOT cover:**
63- Runtime secret injection in Kubernetes (see `engineering/ci-cd-pipeline-builder` for deployment pipeline secrets)
64- Infrastructure-as-code for provisioning Vault clusters or SSM policies (see `engineering/ci-cd-pipeline-builder`)
65- Application-level encryption at rest or in transit (see `engineering/api-design-reviewer` for API security patterns)
66- Identity and access management (IAM) role design or SSO/OIDC provider configuration (see `ra-qm-team/` compliance skills for access control frameworks)
67
68## Integration Points
69
70| Skill | Integration | Data Flow |
71|-------|-------------|-----------|
72| `engineering/ci-cd-pipeline-builder` | Inject secrets from Vault/SSM/Doppler into CI/CD pipeline stages | Rotation playbook outputs feed pipeline secret-update steps |
73| `engineering/dependency-auditor` | Flag dependencies that bundle or require hardcoded credentials | Dependency audit findings trigger secret leak scans on affected repos |
74| `engineering/skill-security-auditor` | Validate that no skill packages ship embedded secrets or credentials | Security audit references this skill's regex patterns for detection |
75| `engineering/codebase-onboarding` | Include `.env.example` setup and secret-manager access in onboarding checklists | Onboarding workflow consumes the `.env` hierarchy and validation script |
76| `engineering/observability-designer` | Monitor authentication failures post-rotation; alert on anomalous secret access | Post-rotation verification metrics flow into observability dashboards |
77| `ra-qm-team/soc2-compliance-auditor` | Demonstrate secret management controls for SOC 2 CC6.1 and CC6.6 criteria | Rotation audit logs and access policies serve as SOC 2 evidence artifacts |