Skip to content

Nix Integration

Anzen ships a Nix module for devshell integration. It generates a wrapped anzen binary with the project config baked in and automatically exports secrets into the shell environment on entry.

Setup

Import the module in your devshell configuration:

{
  imports = [ anzen.lib.module ];

  anzen = {
    environment = "dev";
    groups = [ "shell" ];
    config = {
      project = "my-app";
      provider = "gopass://";
      vars = {
        DATABASE_URL = { description = "Postgres connection string"; groups = [ "shell" ]; };
        API_KEY = { description = "External API key"; groups = [ "shell" ]; };
      };
      environments.dev.vars = {
        DATABASE_URL = { default = "postgres://localhost/dev"; };
      };
    };
  };
}

Module Options

anzen.config

Configuration for anzen, get's converted to toml.

Type:

attribute set

Default value:

{ }

Declared in:

anzen.enable

Enable anzen secret manager.

Type:

boolean

Default value:

anzen.config != {}

Declared in:

anzen.environment

Which environment to load the secrets from. Can contain environment variables.

Type:

string

Default value:

"default"

Declared in:

anzen.groups

Groups to load secrets from, defaults to shell group (add secrets to the shell group to load them in the devshell).

Type:

list of string

Default value:

[
  "shell"
]

Declared in: