🧙♂️⭐️ Varlock inching towards 5k stars - thank you to all the new ones!
First huge bump came from @syntaxfm (thanks @wesbos + @stolinski!)
The current increase in slope is because I finally figured out how X works 😂
😍 varlock codegen for @EffectTS_ config!
Stoked to see the codegen stuff I added enable new integrations from the community.
@danmyles_ - should we migrate this into the monorepo?
github.com/dan-myles/varl…
Nothing solves env loading and validation better than Varlock.
Nub v0.7 adds first-party support. If your repo contains an .env.schema file, Nub uses Varlock to load/validate your environment when running a file or script 👇
🛑 .env.example is an anti-pattern
- copy-paste means it gets out of sync
- mix of real values and placeholders
- source of truth is scattered (real env file, validation code, usage sites, readme)
- no way to understand which items are sensitive
.env.schema is the answer!
Zod for env validation is a great pattern, and it's super nice to avoid env.d.ts generation
I'm a huge Varlock fan though becuase Varlock solves a bunch of other problems beyond just validation. because it wraps your process, Varlock + .env.schema lets you specify LOADING config in addition to just variable validation. that's why its able to do things like stdio-level redaction, encryption, credential brokering, etc. Zod is just a library so it structurally can't do these things.
I'd also argue from an API design standpoint that Varlock's DSL is strictly better than Zod as a mechanism for validation because it's so finely tuned to the kinds of values & validations you commonly need for env vars
@southpolesteve We did some experiments with api key rotation on sites that required logging in w passwords. The answer is have the harness control it and use tool calls, then make sure it’s scrubbed as well in whatever goes back to the model.
No need to fear Full Access for your agents.
1. Use macOS TCC (Transparency, Consent, and Control): lock down your agent’s harness so it cannot access your personal data & .app settings
2. Use @varlockdev to stop it getting at your project keys
3. Use @AutomicVault to stop it getting at your CLI tool credentials and to add granular access control for the rest of your dev-tool stack
@esthor@ImLunaHey@grok We'll soon add cross-device approvals to the proxy with as much granularity as you'd like. So picture an agent running on your machine (or in the cloud) and it only bugs you when it needs your Stripe key specifically to make a request to the refund endpoint.
98 Followers 407 FollowingFormer Head of Engineering @mywebacy. Now making secrets management simple with @capythoughts. Secure your stack @ https://t.co/BR4Fm9kuQ0
241 Followers 3K FollowingSenior Interface Designer at Mercury New Media and freelance photographer. I enjoy sports, traveling with my wife, movies, and our pets.
2K Followers 7K FollowingProblem Slayer 👾⚔️ Cooking up many new things in Biotech 🫁… Tinkerer and multi-modal human. Ex-ChemEng + Healthcare + Pharma. World’s 5th friendliest guy 🏅
35K Followers 685 FollowingCreator of Homebrew. You’re welcome and I apologize. Now building the security layer for what happens when AI agents use it: @AutomicVault
1K Followers 124 FollowingCybersecurity Compliance Without Security Theater — The all-in-one security and compliance platform for SOC 2, ISO 27001, HIPAA, GDPR, CIS, and more.
192K Followers 8K FollowingNYT tech reporter. tell me stuff at [email protected] or [email protected] / Text my signal username with tips: MikeIsaac.38
211K Followers 544 Following- Head of DevRel Engineer at https://t.co/t5PMw0nLYM
- Software Developer
- Rust, Docker, Web Dev
- Docker Captain
- Keynote Speaker
- Building a 1M community...66%
4K Followers 5K FollowingLiving the dream here on Cape Cod with my 🐩 and 👩
Coding ✨ Building Dreams 💖
Full Stack Dev if that's still a thing.
Trying to ride that AI wave 🏄🏻♂️
6K Followers 2K FollowingAI Builder at "startup in stealth."
Previously built @RedwoodJS, https://t.co/bouLHh5N2l, cmdcmd, https://t.co/sfOEdT9hqt, and @_snaplet
11K Followers 100 FollowingTracing reimagined with eBPF and OpenTelemetry.
Instrument your clusters without any code changes.
Get an AI SRE and a robust MCP server.