fnox 1.39.0 lets other tools, starting with mise, get the same environment that fnox exec would give a command. They can run fnox env --json, or use the new fnox-client crate to read it straight from a running daemon's cache.
Added
fnox env --json(#936) by @jdx. Prints a versioned JSON document describing the environment for a command. It hasset(variables),files(as_filecontents for the caller to write, so fnox leaves no files behind),remove(variables to unset),missingandleases. Callers applyremove, thenset, thenfiles.fnox env --json --keys DATABASE_URL,GCP_SA_JSON fnox env --json --describe # list keys and where they can be injected, without resolving anything--for exec(the default) coversenv = trueandenv = "exec"secrets plus leases.--for shellcovers onlyenv = truesecrets and runs no leases.--keys(repeatable, comma-separated) resolves only the listed keys and the secrets they depend on.env = falsesecrets are never printed.- Errors are also printed as JSON on stdout (
config,invalid_keys,resolution) and exit with status 1. --describenever contacts the daemon, creates leases or prompts. With--keys, it checks the keys up front. Its output includesdaemon_enabled.- Resolution works like
fnox exec, using the same daemon cache. The full contract is indocs/reference/env-json.md.--jsonis required for now.
fnox-clientcrate (#937) by @jdx. A lightweight Rust library (no tokio,fnox-coreor provider SDKs) that lets other programs get thefnox env --jsondocument from a running fnox daemon in one Unix-socket round trip. The client is read-only: it never starts the daemon, stores values or triggers provider calls. On a cache miss, the caller should runfnox env --jsonitself so prompts and hardware-key touches still work. On Windows, the crate builds but always reports that no daemon is available.fnox-clientis published alongside fnox with the same version number. To support it, the daemon protocol moves to v6, and the daemon now refuses requests from projects whose config (orFNOX_DAEMON) does not enable it.
Changed
- Daemon socket path changed (#937). After you upgrade, the first daemon-enabled command starts a new daemon with an empty cache. The old daemon keeps running until its idle timeout, and
fnox daemon clearstill reaches it. You don't need to do anything else. fnox execnow builds its environment the same way asfnox env --json(#936). It behaves the same as before, with one exception: it now removes every out-of-scope profile secret from the child's environment, even ones that weren't resolved.
Full Changelog: v1.38.1...v1.39.0
💚 Sponsor fnox
fnox is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.