dotenv

package
v0.5.8 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 11, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package dotenv reads the .env files a project keeps beside its configuration, per policy:dotenv-resolution: .env, .env.local, .env.{env}, .env.{env}.local, then the secret directory a container runtime mounts, layered in that order under the process environment.

The read itself is configbind's, through LoadOptions.EnvFiles in that order with the .local files marked Secret, and EnvSecretDirs for the mount, which is what lets the startup summary and pw doctor name the file a value came from and mask a value a secret source supplied. What stays here is the part configbind is not told: which files a token selects, where the token itself comes from, and the warning for an APP_ENV written into a file APP_ENV chose.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Load

func Load(options configbind.LoadOptions, layer Layer, process []string) (*configbind.LoadResult, error)

Load runs the configuration load with the layer as its dotenv input: the files in order as EnvFiles, the .local ones marked Secret, and the mounts as EnvSecretDirs, so a value from either secret source is masked by origin. The files are handed to configbind by path and read back as places by name, so a summary says ".env.stg.local" whatever directory the load ran against; the secret flag survives the rename.

Types

type Entry

type Entry struct {
	Name  string
	Value string
}

Entry is one assignment in a dotenv file.

func Parse

func Parse(name string, data []byte) ([]Entry, error)

Parse reads dotenv source through system:go-envparse, the parser configbind reads the same files with: NAME=value with an optional export prefix, # comments, and unquoted, single-quoted, and double-quoted text, the last with JSON escapes. A later assignment of the same name wins, as it does between files. There is no ${NAME} expansion; the ${…} form belongs to the TOML layer. Entries come back in name order, so a file reads the same whatever order it was written in.

type File

type File struct {
	// Name is the file's name relative to the directory it was read from,
	// which is how a summary and a report refer to it.
	Name string
	// Path is where it was read from, which is what the load is handed.
	Path    string
	Entries []Entry
	// Local marks the .local member of a pair: ignored by git, and read as a
	// secret source, so every value in it is masked wherever it is shown.
	Local bool
}

File is one dotenv file that exists and parsed.

func Read

func Read(path, name string) (*File, error)

Read parses the dotenv file at path, naming it name in errors and results. An absent file is (nil, nil): nothing was read and nothing is wrong. A file that exists and cannot be read is an error, because a permission problem on a secrets file is never a fallback case.

func (File) Lines

func (f File) Lines() []string

Lines renders the entries as KEY=value lines, the shape os.Environ uses.

type Layer

type Layer struct {
	Files []File
	// SecretDirs are the directories handed to LoadOptions.EnvSecretDirs, only
	// the ones that exist. Their files are read by the load, not here; Environ
	// reads them again for the framework's own environment-carried arrays.
	SecretDirs []string
	// Warnings are what the read noticed and went on from: today, an APP_ENV
	// in the token's own files, which cannot change the token that selected
	// them.
	Warnings []string
}

Layer is the dotenv files read for one token, in read order, and the secret directories the load is asked to read after them.

func ReadLayer

func ReadLayer(dir, env string, secretDirs []string) (Layer, error)

ReadLayer reads the four files of env from dir in the order the load layers them, and notes which of dirs exist to be read as secret mounts. The token is the caller's: this is what pw doctor uses, where the environment to inspect is an option rather than the process's own.

func Resolve

func Resolve(dir string, process []string, secretDirs []string) (Layer, string, bool, error)

Resolve reads the layer for the process itself: the token comes from the process environment, then from .env and .env.local when the process did not set it, and that token selects the second pair. It reports the token and whether anything declared it, on the terms of pwenv.ResolveDeclared.

func (Layer) Environ

func (l Layer) Environ(process []string) []string

Environ composes the environment the way the load does: the files in order, then the secret directories, then the process environment, so a later source wins over an earlier one and an exported variable wins over every file. The framework's own environment-carried arrays read this, since configbind keeps its composed environment to itself.

func (Layer) Names

func (l Layer) Names() []string

Names lists what was read, in order: the files by name, then the secret directories with a trailing separator so a summary reads them as such.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL