본문으로 건너뛰기
전체 영상
q-ring시리즈9 개 에피소드

q-ring 101

q-ring 101 is a short tutorial series on q-ring, the command-line secrets manager and MCP server from I4C Studio. Nine episodes, one command each, none longer than 40 seconds. Each episode page pairs the video with its transcript and a written walkthrough: what the command does, an example you can copy, the risk it removes, and the gotchas the docs call out.

Who it is for

Developers who keep API keys in .env files or shell profiles and now run AI coding agents, such as Claude Code, Cursor, or Kiro, with filesystem and shell access. No security background needed. If you can run npm install, you can follow along.

Follow along

npm install -g @i4ctime/q-ring    # or: brew install i4ctime/tap/qring
qring doctor                      # confirms the keychain works before you start

Use throwaway values while you practice. The episodes were recorded with fake DEMO_ keys for the same reason.

Episodes

  1. Store a secret (qring set): move a key into the OS keychain and list it without printing it.
  2. One key, every environment (qring inspect): separate dev, staging, and prod values under one name.
  3. Run without leaking (qring exec): inject secrets into a command and redact them from its output.
  4. Rotate once, everywhere (qring entangle): link copies so one write updates them all.
  5. Secrets that expire (qring set --ttl): give keys a lifetime that q-ring enforces.
  6. Move a vault (qring teleport): carry secrets to a new machine in one encrypted bundle.
  7. Leave .env behind (qring import): migrate an existing .env file in one command.
  8. Prove who read what (qring audit): a hash-chained log of every access, and how to verify it.
  9. Agents on a leash (qring policy): rules and approvals for what AI agents can touch.

Episodes 1 to 3 cover daily use, 4 to 7 the lifecycle of a key, and 8 and 9 oversight once agents are involved. Every command and flag is in the CLI reference.

에피소드

  1. 0:34
    1화

    q-ring 101 - store a secret (qring set)

    Move an API key out of .env and into the OS keychain with qring set, then list what you stored by name without ever printing a value.

  2. 0:38
    2화

    q-ring 101 - one key, every environment (qring inspect)

    One key name, separate values for dev, staging, and prod. q-ring resolves the right one per context, and qring inspect shows states without values.

  3. 0:32
    3화

    q-ring 101 - run without leaking (qring exec)

    qring exec injects secrets into a command's environment and replaces every known value in its output with [QRING:REDACTED] before logs see it.

  4. 0:32
    4화

    q-ring 101 - rotate once, everywhere (qring entangle)

    Link secrets with qring entangle so a new value written to one reaches its partners, even across projects. One rotation instead of a hunt.

  5. 0:34
    5화

    q-ring 101 - secrets that expire (qring set --ttl)

    Give a secret a lifetime with qring set --ttl. Stale at 75 percent, unreadable once expired, so forgotten tokens stop working on schedule.

  6. 0:33
    6화

    q-ring 101 - move a vault (qring teleport)

    Pack secrets into one AES-256-GCM bundle with qring teleport, send it any way you like, and unpack it into the keychain on the new machine.

  7. 0:28
    7화

    q-ring 101 - leave .env behind (qring import)

    qring import moves every variable in a .env file into the OS keychain in one command, so you can delete the file and keep the same key names.

  8. 0:35
    8화

    q-ring 101 - prove who read what (qring audit)

    q-ring logs every read, write, and delete in a hash-chained audit log. qring audit shows who read what; audit:verify proves nobody rewrote it.

  9. 0:33
    9화

    q-ring 101 - agents on a leash (qring policy)

    A .q-ring.json policy sets which tools, keys, and commands AI agents may use over MCP, and sensitive reads wait for an expiring human approval.