Sign in

varlock.dev

@varlock.dev
107 followers 352 following 65 posts

Building the future of configuration for humans and non-humans varlock.dev

PostsRepliesMedia
varlock.dev @varlock.dev · 19/08/2026
Just happy to see it in the wild! We're here to help if you need anything
000
varlock.dev @varlock.dev · 23/07/2026
check out github.com/dmno-dev/fle... and github.com/dmno-dev/bumpy
github.com
GitHub - dmno-dev/fledgling: 🐣 Create and set up new npm packages w/ trusted (OIDC) publishing - for one package or a whole monorepo
🐣 Create and set up new npm packages w/ trusted (OIDC) publishing - for one package or a whole monorepo - dmno-dev/fledgling
010
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 21/07/2026
Varlock now includes "credential brokering" functionality - your agent (or whatever process) gets only _placeholder_ credentials, and real secrets are swapped in over the wire (MITM proxy). Rules are configured in your existing .env.schema Would love to hear your feedback!
191
Reposted by varlock.dev
Sal Rahman @manlycoffee.techhub.social.ap.brid.gy · 21/07/2026
I was previously tending a booth for a product called Varlock. They're incredibly useful for credentials management. Definitely worth a look. They brand themselves as "credentials management in the AI era". github.com/dmno-dev/varlock
github.com
GitHub - dmno-dev/varlock: AI-safe .env files: Schemas for agents, Secrets for humans.
AI-safe .env files: Schemas for agents, Secrets for humans. - dmno-dev/varlock
062
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 10/07/2026
Super fun chatting with @brandonwhichard.com about varlock. He is a real user - found us through a listener and has been using it ever since. Have a listen! 🎧
031
Reposted by varlock.dev
Brandon Whichard @brandonwhichard.com · 10/07/2026
The .env file: every project has one, almost nobody manages it well. This week I sat down with the founders of varlock to talk about fixing that.
052
varlock.dev @varlock.dev · 10/07/2026
"Everyone has a place for Varlock in their tech stack." Thanks for the great conversation @softwaredefinedtalk.com www.softwaredefinedtalk.com/580
softwaredefinedtalk.com
Varlock: Bringing Order to the Chaos of Environment Variables
Every project has environment variables. Almost nobody manages them well. This week Brandon talks with Phil Miller and Theo Ephraim, who built varlock to fix that — bringing structure and security to ...
040
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 07/07/2026
🧙‍♂️ varlock@1.10 adds arbitrary codegen. As well as built-in support for php, python, go, rust - so you get a fully typed+coerced env loader to use in your code. Plugins can add codegen types - new possibilities to generate for k8s, terraform... anything! varlock.dev/guides/code-...
varlock.dev
Code generation
Generate types and other code from your env schema, and extend it with plugins
161
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 18/06/2026
Say hello to 🐣 fledgling - a new tool to create new npm packages and setup/sync trusted publishing (OIDC) settings. Works great for one offs, but even better in a monorepo! just `npx fledgling`
2177
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 17/06/2026
New varlock+mise guide varlock.dev/integrations... Would appreciate a look from any heavy mise users!
varlock.dev
mise
Install varlock with mise and wire validated env vars into your tasks
062
Reposted by varlock.dev
Darcy Clarke @darcyclarke.me · 01/06/2026
⚡️ We're looking for a DevRel person at @vlt.sh - based in our Toronto 🇨🇦 HQ. You'll work closely w/ me & should love the idea of owning various aspects of product marketing. You'll be vlt's biggest fan & advocate; molding this unique role in a way that plays to your strengths & ours.
22417
Reposted by varlock.dev
Ruy Adorno @ruyadorno.com · 01/06/2026
Toronto friends! we're looking for a DevRel to join the @vlt.sh team there! #hiring #toronto www.vlt.io/careers/deve...
vlt.io
Developer Relations Engineer | Careers | vlt /vōlt/
As a Developer Relations Engineer, you will serve as the bridge between vlt and the global JavaScript community. This role combines technical expertise, community engagement, and developer-focused mar...
1104
varlock.dev @varlock.dev · 21/05/2026
Really happy to hear that! If there's anything else you'd like to see to complete that docker/CI story, just let us know!
030
varlock.dev @varlock.dev · 21/05/2026
Check out our friends at minimal.dev too
minimal.dev
Declarative. Isolated. Reproducible.
Lightning fast, local first sandboxes that secure the supply chain across devs, agents, and CI.
140
varlock.dev @varlock.dev · 21/05/2026
😊
020
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 20/05/2026
This is an awesome writeup! Another helpful precaution I've been yelling about: get EVERY secret out of plaintext. Many malicious scripts are harvesting creds from .env and other config files. varlock.dev can help
varlock.dev
Varlock - AI-safe .env files
AI-safe .env files: schemas for agents, secrets for humans. Validate, secure, and share environment variables with type-safety, leak prevention, and integrations for Next.js, Vite, Astro, and more.
022
varlock.dev @varlock.dev · 08/05/2026
Thanks for the shout out @softwaredefinedtalk.com www.softwaredefinedtalk.com/571 (~47:00)
softwaredefinedtalk.com
The Enterprise Dunbar number
This week, we discuss AI labs driving cloud revenue, hyperscalers laying off instead of building, and kids defeating age verification. Plus, Brandon has too many thoughts on Workday.
000
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 06/05/2026
As of today @varlock.dev has OIDC workload identity support - this means that for some popular combos of deployment platform + secret storage, you no longer need a secret-zero to pull the rest of your sensitive data. check out varlock.dev/guides/oidc/ to get started
varlock.dev
OIDC Workload Identity
Authenticate with secret providers using OIDC tokens from your deployment platform — no long-lived credentials needed
081
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 28/04/2026
Introducing bumpy 🐸 - a new version/release/changelog tool (carefully crafted slop fork of changesets 🦋) Fixes 100s of open issues, much simpler, more flexible. We use it to release @varlock.dev and 25+ linked plugins/libs. bumpy.varlock.dev
4254
varlock.dev @varlock.dev · 28/04/2026
DMNO (varlock) was one of the fastest growing open-source orgs on GitHub in Q1. Thanks for the recognition @supabase.com >commitvc #osscarindex osscar.dev/org/dmno-dev
osscar.dev
DMNO — OSSCAR Q1 2026
DMNO on OSSCAR Q1 2026 with a composite score of 3.000.
092
varlock.dev @varlock.dev · 21/04/2026
A great varlock overview using @1password.bsky.social and @svelte.dev deployed on @vercel.com by @thitemple.me www.youtube.com/watch?v=7n3i...
youtube.com
I Deployed to Vercel and Only Set One Secret — varlock Did the Rest
YouTube video by Thiago Temple
060
varlock.dev @varlock.dev · 20/04/2026
Give varlock.dev a try and you can get the best of both worlds with some extra DX goodies on top
varlock.dev
Varlock - AI-safe .env files
AI-safe .env files: schemas for agents, secrets for humans. Validate, secure, and share environment variables with type-safety, leak prevention, and integrations for Next.js, Vite, Astro, and more.
010
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 17/04/2026
To celebrate @cloudflare.social's epic week - the new @varlock.dev workers integration got a revamp and it is RAD. We totally fixed env vars in workers. varlock.dev/integrations... Full validation, pull from anywhere, set env atomically w/ each deploy. No more mix of .dev.vars/.env/wrangler.toml
varlock.dev
Cloudflare Workers
How to integrate varlock with Cloudflare Workers and Wrangler for secure, type-safe environment management
031
Reposted by varlock.dev
Digital Brain @yourdigitalbrain.bsky.social · 07/04/2026
Unlock the potential of your AI projects with dmno-dev/varlock. Secure your .env files with schemas designed for agents and secrets meant for humans. sinapti.ca/post/en/varlock-typed-sc…
sinapti.ca
Varlock: typed schema environment variables to protect secrets in AI projects, over 3,000 stars on GitHub - Sinaptica
If you use AI agents for programming, you already know the risk: the assistant reads your work environment and, with it, your secrets. Varlock elegantly solves
021
varlock.dev @varlock.dev · 05/04/2026
Sounds familiar 😅
000
varlock.dev @varlock.dev · 01/04/2026
March recap — featuring @nextjs.org (full Turbopack), @cloudflare.social Workers, @expo.dev & plugins for @dashlane.com @hashicorp.com @proton.me me @passbolt.bsky.social (+ KeePass & unix pass): varlock.dev/blog/march-2...
varlock.dev
March 2026 Recap
varlock@0.7.0 adds better plugin authoring with ESM/TypeScript single-file plugins, the Next.js integration gains full Turbopack support, we launch Cloudflare and Expo integrations, and the community ...
020
varlock.dev @varlock.dev · 19/03/2026
Love to see it! Evert from @vlt giving a shout out at TorontoJS
030
varlock.dev @varlock.dev · 16/03/2026
Stoked to be featured in @nickyt.online 's awesome One Tip a Week newsletter which is quickly becoming one of our favourites. one-tip-a-week.beehiiv.com/p/one-tip-a-...
one-tip-a-week.beehiiv.com
One Tip a Week: Stop Shipping Broken Env Config
021
Reposted by varlock.dev
GitHub Trending JS/TS @github-trending-js.bsky.social · 13/03/2026
🚀 Skyrocketing! 🚀 (200+ new stars) 📦 dmno-dev / varlock ⭐ 2,270 (+357) 🗒 TypeScript .env files built for sharing powered by @env-spec decorator comments
github.com
GitHub - dmno-dev/varlock: .env files built for sharing powered by @env-spec decorator comments
.env files built for sharing powered by @env-spec decorator comments - dmno-dev/varlock
142
varlock.dev @varlock.dev · 12/03/2026
Awesome, you too!
010
varlock.dev @varlock.dev · 12/03/2026
We appreciate the post and the feedback @jesse.id ! Those getting started docs are due for an update :) jesse.id/blog/posts/u...
142
Reposted by varlock.dev
David De Sloovere @endevr.be · 11/03/2026
Listened to the pod, but visiting varlock.dev made it so much better... The artwork is awesome! Will try varlock tomorrow! Also starred the repo 🌟
varlock.dev
varlock
141
Reposted by varlock.dev
M̴̛̫̀ã̴̩̙̲͖̖l̴͓̪̮̈́̎p̸͔̘̹̲̘͇͒̽̌̓͗͠e̵̮̙̜̜̝͑̐̕ͅȑ̷͙̰͙̞̐͜͝͠͝c̶̢̱̹̻̚͜í̶̡̝̀̅̽̏ŏ̴̩͓̈̀̂ @malpercio.dev · 11/03/2026
gonna start using varlock.dev just because this site is cool
varlock.dev
varlock
172
varlock.dev @varlock.dev · 11/03/2026
❤️ let us know how it goes, appreciate you checking it out!
010
varlock.dev @varlock.dev · 09/03/2026
😀
030
varlock.dev @varlock.dev · 09/03/2026
🙌
041
Reposted by varlock.dev
Theo Ephraim @theozero.bsky.social · 09/03/2026
varlock was featured on our favourite webdev podcast @syntax.fm today :) Check it out! www.youtube.com/watch?v=M5Ik...
youtube.com
Stop putting secrets in .env
YouTube video by Syntax
4203
varlock.dev @varlock.dev · 07/03/2026
The spec is open, let's chat!
010
Reposted by varlock.dev
GitHub @github.com · 17/02/2026
Who knows how to secure open source better than the maintainers themselves? 🛡️
4277
varlock.dev @varlock.dev · 17/02/2026
Thanks @joshwcomeau.com !
000
varlock.dev @varlock.dev · 17/02/2026
read more about the session here: github.blog/open-source/...
github.blog
Securing the AI software supply chain: Security results across 67 open source projects
The GitHub Secure Open Source Fund helped 67 critical AI‑stack projects accelerate fixes, strengthen ecosystems, and advance open source resilience.
000
varlock.dev @varlock.dev · 17/02/2026
Varlock was one of the projects selected for the @github.com Secure Open Source Fund! We worked with security experts to level up our fundamentals like threat modeling, responsible disclosure, automated scanning, and more. Here's what we learned and shipped: varlock.dev/blog/github-...
varlock.dev
How Varlock Is Leveling Up Security Through the GitHub Secure Open Source Fund
252
varlock.dev @varlock.dev · 12/02/2026
If you want a bit more flexibility, validation and some additional security guardrails, check out varlock.dev. 1Pass was our first plugin :)
000
varlock.dev @varlock.dev · 11/02/2026
if you want a better way to deal with those pesky .env files, check out varlock.dev, we're shipping some more plugins this week for the different secrets management providers too!
000
varlock.dev @varlock.dev · 06/02/2026
What if you could have your cake and eat it too? Load and validate that .env with varlock.dev and then migrate to @1password.bsky.social incrementally. You can even load local overrides via their local .env file destination
000
varlock.dev @varlock.dev · 22/01/2026
catching up takes a day, keeping up takes a lifetime 😅
010
varlock.dev @varlock.dev · 10/12/2025
Really great chatting with @thisdotlabs.bsky.social @robocel.bsky.social about all things varlock.dev
011
varlock.dev @varlock.dev · 02/12/2025
I'm told keeping secrets out of plaintext is hot
000
varlock.dev @varlock.dev · 02/12/2025
we have some nice examples on how to securely load secrets to use with opencode here varlock.dev/guides/ai-to...
varlock.dev
AI Tools
Using varlock with AI tools - preventing secrets from being leaked to your AI agents
110
varlock.dev @varlock.dev · 21/10/2025
And you can use varlock.dev to validate them too!
varlock.dev
varlock
000