Theo Ephraim

@theozero.bsky.social

🧙‍♂️🪄🔒 https://varlock.dev Open sourcerer, devtools builder, entrepreneur

Varlock now includes "credential brokering" functionality - your agent (or whatever process) gets only _placeholder_ credentials, and real secrets are swapped in over the wire (MITM proxy). Rules are configured in your existing .env.schema Would love to hear your feedback!

Random q - do folks out there care / think about how much plastic they are exposed to? Talking things like coffee gear, water bottles / mugs, cookware, baby products. Do you research before you buy? Would you like to minimize but takes too much work? Never think about it? I'm cooking something :)

Building a new CLI tool? Here is your toolkit: - gunshi (cli framework) - clack/prompts (cli prompts) - lefthook (git hooks) - tsdown (ts build tool) - bumpy (changelog + publishing) - fledgling (bonus) - for initial npm claim and oidc setup

Super fun chatting with @brandonwhichard.com about varlock. He is a real user - found us through a listener and has been using it ever since. Have a listen! 🎧

Software Defined Talk@softwaredefinedtalk.com · 4w ago

Every project has environment variables. Almost nobody manages them well. This week @brandonwhichard.com talks with Phil Miller and @theozero.bsky.social, who built varlock to fix that — bringing structure and security to the humble .env file. https://www.softwaredefinedtalk.com/580

varlock will soon support arbitrary codegen registered in plugins. Opens up fun possibilities - generate zod schema, k8s configmap/secret split based on what's marked @sensitive, terraform vars Plus new built-in env generation for rust, go, python, php. Excited to see how you will use it! 🧙‍♂️✨

varlock credential broker is coming very soon! child process (usually AI agent) gets _placeholders_, swapped for real creds at the network boundary. Rules managed from your .env.schema - use our existing plugins to pull from anywhere. Can't wait to share it :)

npm staged publishing approval tool MVP is working. Batch approve multiple packages, multi-sig approval policies, audit trails, batches created in CI via OIDC. NPM token encrypted by passkeys so we never see them. Using staged publishing? Wanting to but avoiding because its clunky? Let me know!

My new npm staged publishing approval tool is called "stageflight" - HMU if you want to beta test! Provides batch approvals, multi-sig policies w/ audit trails, approvers don't need publishing rights. Cloud-hosted but secrets encrypted w/ your passkeys. optional ai review too in future

Working on something pretty rad that’s going to help make npm staged publishing feel much nicer - and even more secure. Like/comment/DM if this is up your alley and you want to help me beta test.

Doesn't exactly inspire confidence when things show an error message even when they work. A few npm interactions regularly do this for me - approving staged publishing being one of them.

Bild

Say hello to 🐣 fledgling - a new tool to create new npm packages and setup/sync trusted publishing (OIDC) settings. Works great for one offs, but even better in a monorepo! just `npx fledgling`

Looking at adding long-lived pre-release channels to bumpy.varlock.dev (one most confusing/complained about parts of changesets 🦋) not implemented yet, but here is the plan -- github.com/dmno-dev/bum... If anyone has thought about this deeply and has any feedback I'd be very grateful!

GitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool

🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy

bumpy.varlock.dev

when starting a new project repo, choosing a tech stack, etc, i try to always ask the hard and important questions right up front, such as: “how do i work this?”, “what is that beautiful house?”, “where does that highway go to?”, “am I right? am I wrong?”, and “my god! what have I done?”