Environments
vaultic env — create, inherit, diff, promote, lock, and manage change approvals.
vaultic env <subcommand> — create, inherit, diff, promote, lock, and manage change approvals.
env list
Lists environments for the current project — marks the default with *, and tags
inherits <slug>, locked, and ephemeral, expires <date> where applicable. No options.
env create
env create <slug>| Flag | Description |
|---|---|
--inherits <environment> | Inherit unset keys from this environment |
--ephemeral | Flag as an ephemeral/preview environment (needs --ttl-days or --expires-at) |
--ttl-days <days> | Auto-expire this many days from now |
--expires-at <iso> | Auto-expire at this exact ISO timestamp |
vaultic env create dev-alice --inherits developmentAn environment like dev-alice falls through to development for anything it doesn't
explicitly override.
env duplicate
env duplicate <source> <target>| Flag | Description |
|---|---|
--keys-only | Copy keys only, values left blank |
--link | Link mode: inherit from source instead of copying values |
Mode resolution: --link > --keys-only > default (copy values). Duplicate in link mode is
create + inherit in one step, with no values copied.
env diff
env diff <from> <to>| Flag | Description |
|---|---|
--reveal |
Prints added/removed/changed/unchanged key lists between two environments.
env promote
env promote <from> <to>| Flag | Description |
|---|---|
--yes | Skip the confirmation prompt |
Diffs from → to, shows the planned creates/updates, prompts for confirmation (unless
--yes), then copies the added/changed values up. Typical for staging → production.
env rm
env rm <slug>| Flag | Description |
|---|---|
--yes | Skip the confirmation prompt |
Deletes an environment. A base environment (a column — see the web app's environment board) can't be deleted this way; neither can a sandbox that still has children of its own — delete or re-parent those first.
env lock / env unlock
env lock <slug>
env unlock <slug>No options. A locked environment rejects direct writes (secrets set/delete) — they become
pending change proposals instead, requiring approval.
env proposals
env proposals <slug>| Flag | Description |
|---|---|
--status <status> | pending | approved | rejected (default pending) |
env approve / env reject
env approve <slug> <proposalId>
env reject <slug> <proposalId>No options.