CLI Reference
Global Flags
| Flag | Env Var | Default | Description |
|---|---|---|---|
--config |
ANZEN_CONFIG |
Override .anzen.toml path |
|
--project |
ANZEN_PROJECT |
Override project path | |
-e, --env |
ANZEN_ENV |
default |
Environment to use |
-g, --group |
ANZEN_GROUPS |
Groups to load (repeatable) | |
--log-level |
ANZEN_LOG_LEVEL |
Log level: trace, debug, info, warn, error | |
-n, --dry-run |
ANZEN_DRY_RUN |
false |
Simulate operations without making any changes |
All flags can be set via environment variables with the ANZEN_ prefix.
Commands
anzen init
Creates a .anzen.toml from a sample template in the current directory (or path specified by --config).
anzen init
anzen --config path/to/.anzen.toml init
anzen trust
Trusts the current project's configuration. Computes a SHA-256 hash of the config file and stores it in the global state. Prompts for:
- Confirmation that the config file is safe
- Provider selection (project default, global alias, or raw URI)
- Whether to allow secret generation
If the project was previously trusted, offers to just update the hash or fully reconfigure.
anzen distrust
Removes the current project from the trust database.
anzen get <SECRET_NAME>
Retrieves and prints a single secret's resolved value to stdout (no trailing newline).
anzen get DATABASE_URL
anzen -e prod get DATABASE_URL
anzen set <KEY>
Stores a secret value in the provider. The value is read from an interactive password prompt. If stdin is a pipe, reads from stdin instead.
anzen set API_KEY
echo "secret-value" | anzen set API_KEY
anzen -e prod set API_KEY
Flags:
| Flag | Description |
|---|---|
--stdin |
Read value from stdin (auto-detected for pipes) |
anzen run [flags] -- <command>
Resolves secrets for the active environment/groups and executes the command with them injected as environment variables.
anzen run -- go test ./...
anzen -e test -g database run -- go test ./...
anzen -e dev run -s 'echo $VARIABLE'
Flags:
| Flag | Description |
|---|---|
-s, --shell |
Wrap command in sh -c (enables shell expansion) |
anzen export
Prints resolved secrets as KEY=VALUE pairs to stdout.
anzen export
anzen export --shell
anzen -e prod -g web export --shell
Flags:
| Flag | Description |
|---|---|
--shell |
Prefix each line with export and quote values |
Useful with eval:
eval "$(anzen export --shell)"
anzen generate [SECRET_NAME...]
Generates secrets that have a generate block in their definition. By default, only generates secrets not yet present in the provider.
anzen generate SECRET_KEY
anzen generate --all
anzen generate --all --no-fetch
Flags:
| Flag | Description |
|---|---|
--all |
Generate all generatable secrets |
--no-fetch |
Skip checking provider for existing values |
--insecure-allow-generation |
Skip confirmation prompt (for CI/automation) |
anzen copy [secrets...]
Copies secrets between providers. If no secret names are given, copies all secrets defined in the current environment.
anzen copy --from os-keychain:// --to gopass://
anzen copy --from project --to gopass:// API_KEY DATABASE_URL
Flags:
| Flag | Required | Description |
|---|---|---|
--from |
yes | Source provider URI or project |
--to |
yes | Destination provider URI |
Using project as a provider value resolves to the project's configured provider.
anzen status
Shows current session info, project trust state, and provider status.
anzen summary
Displays the full project configuration: variables, environments, groups, and their properties.
anzen validate
Validates global config, global state, and the project config file. Exits non-zero on parse errors.