github jdx/fnox v1.39.0
v1.39.0: fnox env --json and a daemon client crate for other tools

5 hours ago

fnox 1.39.0 lets other tools, starting with mise, get the same environment that fnox exec would give a command. They can run fnox env --json, or use the new fnox-client crate to read it straight from a running daemon's cache.

Added

  • fnox env --json (#936) by @jdx. Prints a versioned JSON document describing the environment for a command. It has set (variables), files (as_file contents for the caller to write, so fnox leaves no files behind), remove (variables to unset), missing and leases. Callers apply remove, then set, then files.
    fnox env --json --keys DATABASE_URL,GCP_SA_JSON
    fnox env --json --describe   # list keys and where they can be injected, without resolving anything
    • --for exec (the default) covers env = true and env = "exec" secrets plus leases. --for shell covers only env = true secrets and runs no leases.
    • --keys (repeatable, comma-separated) resolves only the listed keys and the secrets they depend on. env = false secrets are never printed.
    • Errors are also printed as JSON on stdout (config, invalid_keys, resolution) and exit with status 1.
    • --describe never contacts the daemon, creates leases or prompts. With --keys, it checks the keys up front. Its output includes daemon_enabled.
    • Resolution works like fnox exec, using the same daemon cache. The full contract is in docs/reference/env-json.md. --json is required for now.
  • fnox-client crate (#937) by @jdx. A lightweight Rust library (no tokio, fnox-core or provider SDKs) that lets other programs get the fnox env --json document from a running fnox daemon in one Unix-socket round trip. The client is read-only: it never starts the daemon, stores values or triggers provider calls. On a cache miss, the caller should run fnox env --json itself so prompts and hardware-key touches still work. On Windows, the crate builds but always reports that no daemon is available. fnox-client is published alongside fnox with the same version number. To support it, the daemon protocol moves to v6, and the daemon now refuses requests from projects whose config (or FNOX_DAEMON) does not enable it.

Changed

  • Daemon socket path changed (#937). After you upgrade, the first daemon-enabled command starts a new daemon with an empty cache. The old daemon keeps running until its idle timeout, and fnox daemon clear still reaches it. You don't need to do anything else.
  • fnox exec now builds its environment the same way as fnox env --json (#936). It behaves the same as before, with one exception: it now removes every out-of-scope profile secret from the child's environment, even ones that weren't resolved.

Full Changelog: v1.38.1...v1.39.0

💚 Sponsor fnox

fnox is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.

If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.

Don't miss a new fnox release

NewReleases is sending notifications on new releases.