Cloud sandboxes

Env Sources — Share Secrets from Your iPhone

Last updated: 2026-09-21

Every project needs secrets — API keys, database URLs, tokens. You should never commit them or leave them on a cloud machine. Env Sources lets RepoGo pull an encrypted snapshot from your Mac to your iPhone, then give your services those values only after you approve. The service borrows them in memory for as long as it runs.

The idea splits cleanly in two:

  • Your repo says what it needs — a service in environment.json lists named sources with envFrom: ["my-secrets"]. Just names. Nothing sensitive ever goes in the repo.
  • You say where each name lives — in the app, you point my-secrets at a Mac and a .env file on it. Saving pulls a protected snapshot to that iPhone.

The mapping is private to your RepoGo account. The secret contents live in the original Mac file and the device-only Keychain on each iPhone where you pull them. The repo only ever contains the name.

The mental model#

An env source is a named pointer plus an iPhone snapshot: a handle (like api-secrets) is bound to one .env file on one of your Macs, and the app securely pulls its contents to your iPhone. It says "when something asks for api-secrets, let me approve sharing the snapshot I pulled from this file."

HandleMacFile
api-secretsMacBook Pro~/secrets/acme/.env
stripeMac Studio~/secrets/acme/.env.stripe

A repo's environment.json references the handle and nothing else:

json
{ "name": "api", "cmd": "bun install && bun start", "envFrom": ["api-secrets"] }

Setting one up#

Open Env Sources in the app (left drawer → profile icon → Connections → Env Sources). Tap Add Source and walk three steps:

  1. Pick the Mac. Choose which of your paired Macs the file lives on. If you only have one, it's chosen for you. RepoGo always reads from the Mac you pick — it never guesses or searches your other Macs.
  2. Browse for the file. Your Mac's home folder opens as a file tree. Tap a folder to expand it in place — the app reads that one folder as you open it, so nothing scans your whole disk. By default the tree shows only .env files (.env.example is skipped) and skips hidden folders. The filter button in the top right has two switches: Show All Files, if you keep secrets under a custom name, and Show Hidden Folders, if the file lives somewhere like ~/.config. Tap the file to continue.
  3. Name the handle. Give the source a short name — this is the string your repo uses in envFrom. Handles are slugs: lowercase letters, numbers, and dashes (api-secrets, stripe, web-env). RepoGo suggests one from the folder the file sits in; keep it or edit it.

Save, and RepoGo reads the file from the selected Mac before the source shows up in your list. You can then approve requests from this iPhone even when that Mac is asleep or disconnected.

When the Mac file changes, tap the refresh button beside the source to pull the latest snapshot. RepoGo does not silently replace it, so you decide when changed credentials reach this iPhone.

To remove a source, tap its trash button. Deleting removes both the private pointer and this iPhone's snapshot; the file on your Mac is untouched. Any service still referencing that handle simply starts without those variables (see below).

What happens when a service starts#

When a service with envFrom boots — on a fresh environment, or every time it wakes — RepoGo:

  1. Looks up the handle in your private Env Sources.
  2. Asks you to approve sharing it. (If your phone is asleep, you get a notification.)
  3. Reads the snapshot on the approving iPhone. If that iPhone does not have one yet, RepoGo pulls it from the bound Mac first.
  4. Loads the variables into the service in memory and starts it.

Your secrets are never written to the environment's disk and never captured in an environment snapshot. They are copied only to the iPhone's device-local Keychain. When the environment sleeps, its in-memory copy is gone; on the next wake, you approve sharing the iPhone snapshot again.

If you decline, the service still starts — just without those variables. The same is true when the approving iPhone has no snapshot and its bound Mac is unreachable. A service that genuinely needs them will print the error in its terminal tab, where you can see it, fix it, and restart.

Great for teams#

Because the repo holds only the name of a source, a teammate who clones the same project just points that name at their own file on their own Mac — once, in the app. No shared secrets, no per-person edits to environment.json, nothing to coordinate. The same committed config works for everyone, each person resolving the handle to their own credentials.

Multiple Macs#

You choose which Mac each source pulls from when you create it, so different sources can come from different machines — api-secrets from your MacBook, stripe from your Mac Studio. That Mac must be reachable for the initial pull and whenever you refresh. It does not need to be reachable when you later approve sharing a snapshot already saved on the iPhone.

How it fits with environment.json#

Env Sources is the secrets half of Start Services Automatically. The two meet at one field:

  • In environment.json, envFrom: ["name", ...] lists the sources a service needs.
  • In the app, Env Sources binds each name to a Mac and a file.

Everything else about a service — cmd, target, expose, dependsOn — is described in the startup-services doc. Env Sources only governs where the secrets come from.

Next steps#