A fast, modern Rust CLI for linting .env files and ensuring environment synchronization across your entire DevSecOps stack.
- Lint - Detects duplicate keys, invalid syntax, empty values, trailing whitespace, unsorted keys
- Compare - Identifies missing keys across multiple environment files
- Fix - Auto-fix issues with
--commitand--prflags for CI integration - TUI - Interactive terminal UI for comparing and merging
.envfiles
| Integration | Command | What it checks |
|---|---|---|
| Kubernetes | envcheck k8s-sync |
SecretKeyRef/ConfigMapKeyRef vs .env |
| Terraform | envcheck terraform |
TF_VAR_* variable usage |
| Ansible | envcheck ansible |
lookup('env', 'VAR') calls |
| GitHub Actions | envcheck actions |
env: blocks in workflows |
| Helm | envcheck helm |
SCREAMING_SNAKE_CASE in values.yaml |
| ArgoCD | envcheck argo |
plugin.env and kustomize.commonEnv |
- Text - Colored terminal output (default)
- JSON - Machine-readable for pipelines
- GitHub - Native GitHub Actions annotations
- SARIF - GitHub Security tab integration
- PR Comment - Markdown for PR/MR comments
cargo install envchecknpm install -g @envcheck/cli
# or use without installing
npx @envcheck/cli lint .envbrew tap envcheck/tap
brew install envcheckDownload pre-built binaries from GitHub Releases.
envcheck lint .env
envcheck lint .env .env.local .env.prod
envcheck lint .env --format json
envcheck lint .env --format sarif > results.sarifenvcheck compare .env.example .env.prodenvcheck fix .env # Sort keys, remove whitespace
envcheck fix .env --commit # Auto-commit changes
envcheck fix .env --pr # Create a PR with fixesenvcheck tui .env.example .env .env.prodenvcheck k8s-sync k8s/*.yaml --env .env.exampleenvcheck terraform infra/ --env .envenvcheck ansible playbooks/ --env .envenvcheck actions .github/workflows --env .envenvcheck helm charts/myapp --env .envenvcheck argo argocd/apps --env .envenvcheck completions bash > /etc/bash_completion.d/envcheck
envcheck completions zsh > ~/.zsh/completions/_envcheck
envcheck completions fish > ~/.config/fish/completions/envcheck.fish| ID | Rule | Severity | Description |
|---|---|---|---|
E001 |
Duplicate Key | Error | Key defined multiple times |
E002 |
Invalid Syntax | Error | Line is not KEY=VALUE |
W001 |
Empty Value | Warning | Key has no value |
W002 |
Trailing Whitespace | Warning | Line ends with whitespace |
W003 |
Unsorted Keys | Warning | Keys are not alphabetically sorted |
W004 |
Missing Key | Warning | Key missing in comparison file |
W005 |
K8s Missing Env | Warning | Key in K8s not in .env |
W006 |
Unused Env | Info | Key in .env not in K8s |
Create .envcheckrc.yaml or .envcheckrc.toml in your project root:
# .envcheckrc.yaml
rules:
disable:
- W003 # Don't warn about unsorted keys
warnings_as_errors: false
ignore:
- "*.local"
- ".env.development"
format: text
files:
- .env
- .env.example# Ignore patterns (like .gitignore)
*.local
.env.development
tests/fixtures/**
JSON Schema for IDE autocompletion: https://envcheck.github.io/schema/envcheckrc.json
- uses: envcheck/action-envcheck@v1
with:
command: lint
args: .env.example .env
format: githubrepos:
- repo: https://github.com/envcheck/envcheck
rev: v0.1.0
hooks:
- id: envcheck-lint
args: [".env.example", ".env"]
- id: envcheck-k8s
args: ["k8s/*.yaml", "--env", ".env.example"]envcheck:
image: rust:latest
script:
- cargo install envcheck
- envcheck lint .env --format json > envcheck-report.json
artifacts:
reports:
codequality: envcheck-report.jsonenvcheck/
βββ envcheck/ # Core Rust CLI (this repo)
βββ envcheck-npm/ # npm wrapper package
βββ action-envcheck/ # GitHub Action
βββ envcheck.github.io/ # Documentation website
- Parallel processing with Rayon
- Zero-copy parsing with
Cow<str>for reduced allocations - Benchmarks available via
cargo bench
parse_env_file: ~3.3 Β΅s
lint_rules: ~2.3 Β΅s
| Feature | envcheck | dotenv-linter |
|---|---|---|
| Linting | β | β |
| Compare | β | β |
| Auto-fix | β + commit/PR | β |
| K8s Sync | β | β |
| Terraform | β | β |
| Ansible | β | β |
| GitHub Actions | β | β |
| Helm | β | β |
| ArgoCD | β | β |
| TUI | β | β |
| SARIF | β | β |
| Config files | β | β |
| Shell completions | β | β |
- envcheck-npm - npm wrapper
- action-envcheck - GitHub Action
- envcheck.github.io - Documentation
MIT