Nothing solves env loading and validation better than Varlock. Nub v0.7 adds first-party support. If your repo contains an .env.schema file, Nub uses Varlock to load/validate your environment when running a file or script 👇
🛑 .env.example is an anti-pattern - copy-paste means it gets out of sync - mix of real values and placeholders - source of truth is scattered (real env file, validation code, usage sites, readme) - no way to understand which items are sensitive .env.schema is the answer!

Sep 6, 2026 · 8:17 AM UTC

12
9
370
32,884
Sort replies: Relevant Recent Liked
Replying to @colinhacks
If you want granular control over who gets to decrypt that .env, eg. your agent must ask permission, but your terminal gets auto-approved. Then I added that to Automic Vault a couple weeks ago. Should just work with `nub`.
2
1
5
666
nice this rocks!
4
307
Replying to @colinhacks
What about fnox? 🥲
1
1
252
these are complementary, you can use them together 👍
1
204
Replying to @colinhacks
Hell yeah
2
287
Replying to @colinhacks
But is it worth a third party dependency ... ?
1
200
Replying to @colinhacks
is process.env typed after this? that's the part i'd actually switch for
11
Replying to @colinhacks
You are really tempting me to switch to nub
371
Replying to @colinhacks
The normal command doing the validation is the win for me. A check that depends on everybody remembering a special prefix eventually becomes a README suggestion.
2
Replying to @colinhacks
what about @stashbase
10
Replying to @colinhacks
Definitely going to look at this. Already before AI-agents, .env files were an anti-pattern.
92