ferrvault reads the secrets of one vault environment and prints them, or runs a command with them in its environment. It authenticates with a service-account token, so it sees exactly the environment that token is bound to.

Install

The CLI builds from source with Cargo:

cargo install --git https://github.com/FerrLabs/FerrVault ferrvault-cli

Prebuilt binaries are not published yet.

Log in

ferrvault login --url https://api.ferrvault.com

The token is read from standard input, or from --token or FERRVAULT_TOKEN. It is checked against the API before anything is stored, then kept in the operating system's credential store: Credential Manager on Windows, Keychain on macOS, libsecret on Linux. There is no fallback to a file on disk, so on Linux without a keyring login fails.

In CI, skip login and set FERRVAULT_URL and FERRVAULT_TOKEN in the environment.

Commands

Command What it does
ferrvault whoami Shows the vault, role, label and expiry of the token.
ferrvault list Lists secret names and versions, never values.
ferrvault get NAME Prints one value.
ferrvault get --all Prints every value, as --format env, dotenv or json.
ferrvault get --names A,B Prints a subset.
ferrvault exec -- CMD Runs CMD with every secret as an environment variable.
ferrvault set NAME VALUE Creates a secret, or rotates it with --update. Needs writer.
ferrvault delete NAME Deletes a secret, keeping its versions. Needs writer.
ferrvault logout Forgets the stored URL and token.

ferrvault exec never writes values to disk, which makes it the safest way to hand secrets to a process:

ferrvault exec -- ./run-migrations.sh
ferrvault exec --names DATABASE_URL,STRIPE_KEY -- npm run start

Private deployments

Flag Effect
--ca-cert PATH Trusts an extra CA certificate (PEM).
--client-cert, --client-key Presents a client certificate for mutual TLS.
--pin-sha256 HASH Pins the server certificate by the SHA-256 of any certificate in its chain.

Each flag has a matching FERRVAULT_* environment variable; ferrvault --help lists them.