Guides

The awkward parts of working with environment variables — the ones that usually get solved with a Slack DM and a quiet hope that nobody scrolls back.

Handling secrets

How to share a .env file securely

Why Slack and email are the wrong pipe, what a safe hand-off actually needs, and three ways to do it — including one that needs no account on the other end.

How to remove a .env file from git history

You committed .env. Rewriting history is the second thing to do — this is the first, and the order matters more than the commands.

Syncing environments

How to sync environment variables with Vercel

Pull what is already in your Vercel project into a single source of truth, and keep local, preview and production from drifting apart.

How to sync environment variables with Railway

Move Railway's variables into version-tracked storage, and get them onto a new laptop without a copy-paste session.

How to sync environment variables with Render

Import a Render service's environment, then keep the local .env and the deployed one honest about their differences.

Migrating in

How to migrate from Doppler

Projects and configs map onto Sink's projects and environments almost directly, so nothing gets renamed on the way in.

How to migrate from Infisical

Authenticate as a machine identity, pick a region and a secret path, and import one environment at a time.

How to migrate from AWS Secrets Manager

The read-only IAM policy to use, how myapp/prod/db-password becomes a variable name, and what happens to secrets holding JSON.

How to migrate from Azure Key Vault

Register an app, give it Key Vault Secrets User, and import a vault — including why the vault name is typed rather than picked.

Choosing a tool

Looking for a Doppler alternative

What to actually compare when you are shopping for a secret manager, and where Sink sits among them.