Skip to content

feat: add kp-env and kpxc-cli for KeePassXC-backed secrets - #49

Merged
JustMaris merged 2 commits into
mainfrom
feat/kp-env
Sep 24, 2026
Merged

JustMaris merged 2 commits into
mainfrom
feat/kp-env

Conversation

@JustMaris

Copy link
Copy Markdown
Member

Summary

  • New ~/.local/bin/kp-env <name>. It prints export VAR=value for every entry in a KeePassXC env/<name> group, replacing the per-repo .env files. The infra repos call it through just kp <recipe|command>.
    • It asks the running KeePassXC app through kpxc-cli (browser-integration protocol), so Touch ID works. If that finds nothing, it falls back to keepassxc-cli on the .kdbx, which prompts for the master password.
    • It includes an assert-based self-check: kp-env --selftest.
  • kpxc-cli (mietzen/tap/keepassxc-cli) is added to the Brewfile, under the same gate as the keepassxc cask.
  • CLAUDE.md gave the wrong target for the rendered Brewfile. It's ~/.Brewfile, and run_onchange_brew-bundle installs it on apply.

Test plan

  • kp-env --selftest
  • just kp plan in proxmox-opentofu showed no changes, with secrets loaded from KeePassXC
  • chezmoi execute-template < dot_Brewfile.tmpl renders the tap and formula

kp-env prints export lines for a KeePassXC env/<name> group, replacing
per-repo .env files (eval "$(kp-env proxmox-opentofu)"). It uses kpxc-cli
against the running app when available (Touch ID), otherwise keepassxc-cli
on the .kdbx. kpxc-cli is installed alongside the keepassxc cask.
dot_Brewfile.tmpl renders to ~/.Brewfile, not ~/Brewfile, and apply
installs it via run_onchange_brew-bundle.
@JustMaris
JustMaris merged commit 970e0a1 into main Sep 24, 2026
8 checks passed
@JustMaris
JustMaris deleted the feat/kp-env branch September 24, 2026 19:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant