跳到主内容
全部视频
q-ring0:28

q-ring 101 - leave .env behind (qring import)

qring import moves every variable in a .env file into the OS keychain in one command, so you can delete the file and keep the same key names.

指南

What it does

qring import <file> parses a .env file and stores every variable in it as a q-ring secret in your OS keychain. It understands standard dotenv syntax, including comments, quoted values, and escape sequences. After that the file has no job left, so you delete it, and the keys keep working through qring get, qring exec, or qring run.

Try it

# Preview: what would be imported, nothing written
qring import .env --dry-run

# Import into this project's scope, leaving existing keys alone
qring import .env --project --skip-existing

# Import a stage-specific file into one environment state
qring import .env.staging --project --env staging

# Check, then remove the file
qring list --project
rm .env

To keep the familiar workflow, run your dev server through qring exec -- npm run dev. If a tool insists on reading a .env, commit qring:// references in it instead of values (for example DATABASE_URL=qring://project/DATABASE_URL) and start the tool with qring run.

Why it matters

A gitignored .env is still plaintext that any process running as you can read. The common leak paths are mundane: git add -A after the ignore file changes, an agent running cat .env to debug a failing call, an .env.example built by copying the real file. Moving the values into the keychain removes the file those paths depend on, without renaming a single variable in your code.

Gotchas and good to know

  • Without --project, keys go to global scope. If two repositories both have a DATABASE_URL, import each with --project from its own directory so they do not overwrite each other.
  • --skip-existing protects keys you have already stored. Without it, matching names are overwritten with the file's values.
  • Deleting the file does not clean history. If the .env was ever committed, the values are still in git, and those keys should be rotated.
  • The import_dotenv MCP tool only accepts raw content and never reads files from disk, so an agent cannot use it to read arbitrary local files.
  • Need a real .env again, for a tool that cannot do without one? qring env:generate writes one from your .q-ring.json manifest. Treat that output as a secret and delete it when you are done.

Go deeper

文字稿

选择时间戳,即可从该时间点开始播放视频。

  1. 0:01Every .env file is a leak waiting for a git add.
  2. 0:07q-ring imports the whole file into your OS keychain in one command.
  3. 0:12Then you delete the file, and keep the secrets.
  4. 0:17Same keys, same workflow.
  5. 0:19Just nothing left on disk to steal.