Skip to content

Add exec-env, exec-file, and decrypt --extract verbs - #11

Merged
dcadolph merged 1 commit into
mainfrom
feat/exec-verbs
Jul 8, 2026
Merged

dcadolph merged 1 commit into
mainfrom
feat/exec-verbs

Conversation

@dcadolph

@dcadolph dcadolph commented Jul 8, 2026

Copy link
Copy Markdown
Owner

Add exec-env, exec-file, and decrypt --extract verbs

Summary

Adds three CLI verbs that close the runtime and scripting gaps against the SOPS
binary. No library or on-disk format changes. The SOPS format is untouched.

Changes

  • exec-env PATH COMMAND decrypts PATH, flattens it to KEY=VALUE pairs, and runs
    COMMAND through /bin/sh with those pairs appended to the current environment.
    Supports dotenv, YAML, and JSON with a flat scalar map. YAML and JSON output is
    sorted by key. Dotenv preserves file order.
  • exec-file PATH COMMAND decrypts PATH to a 0600 file in a fresh 0700 temp
    directory, substitutes the first "{}" in COMMAND with the quoted path (appends
    when absent), runs it, and removes the directory on exit. The --filename flag
    overrides the temp file name.
  • decrypt --extract EXPR walks a path expression of ["key"] and [N] steps after
    decrypt and prints the selected node. Scalars print raw. Maps and slices
    re-encode in the file format. Incompatible with --in-place.

Exit codes

Both exec verbs propagate the child process exit code. A new exitError type
carries the code up to main, which exits with it and suppresses the usage banner.
The exec commands set SilenceUsage and SilenceErrors so main is the single error
renderer.

Testing

  • Table-driven unit tests cover env flattening (dotenv, YAML, JSON, plus the
    non-scalar and unsupported-format error paths), "{}" substitution, temp-file
    naming, exit-code propagation, extract path parsing, and extract traversal
    across YAML and JSON.
  • End-to-end verified with a real age round-trip: exec-env reaches the child
    environment, exec-file substitutes the decrypted path, decrypt --extract
    returns scalars, array elements, and re-encoded subtrees, and a missing key
    exits non-zero.
  • go build, go vet, golangci-lint, and the full unit suite pass.

Docs

cmd/README.md documents all three verbs with flags, examples, and security
models.

@dcadolph
dcadolph merged commit f3ed411 into main Jul 8, 2026
9 checks passed
@dcadolph
dcadolph deleted the feat/exec-verbs branch July 8, 2026 19:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant