UnENVerse

Quickstart

From nothing to a vault you can trust in about fifteen minutes. This page uses the command line so every step is copy-and-paste; the desktop app does the same things from its menus. The commands below were run against the 0.42.5 release on a clean machine.

Use a throwaway folder and made-up values while you learn. Passing a password on the command line is fine for a demo, but real use should prompt for it or read the UNV_PASSWORD variable. If UNV_SERVER_URL is set in your shell, unset it first: it sends commands to that server instead of your local vault.

  1. 1. Install

    Download the CLI archive from the download page, verify it, and unpack it.

    tar xzf unv-0.42.5-linux-x86_64.tar.gz
    ./unv --version

    On Windows, unzip unv-0.42.5-windows-x86_64.zip and run unv.exe. Or install the desktop app, which creates the same vault.

  2. 2. Create a vault

    Your master password goes through Argon2id to make the key. There is no reset: a forgotten master password cannot be recovered. The vault is two files, vault.db and vault.salt. Keep them together; a database without its salt cannot be opened by anyone.

    export UNV_PASSWORD='choose-a-long-passphrase'
    ./unv --db-path ./demo/vault.db --init status

    Without --db-path the CLI uses the desktop app's vault, so the app and the CLI share one vault.

  3. 3. Import a .env file

    printf 'DB_PASSWORD=made-up-value\nAPI_TOKEN=tok_made_up_0123456789\n' > .env
    ./unv --db-path ./demo/vault.db project add demo
    ./unv --db-path ./demo/vault.db import .env --project demo
    ./unv --db-path ./demo/vault.db list

    The list shows names and types, never values. Values are redacted by default everywhere in the CLI.

  4. 4. Render the file back and compare

    A project holds config chunks. An env_file chunk refers to your entries with ${ref}, so the value lives in one place.

    ./unv --db-path ./demo/vault.db project chunk add demo app.env --type env_file
    ./unv --db-path ./demo/vault.db project chunk set demo app.env 'DB_PASSWORD=${DB_PASSWORD}' 'API_TOKEN=${API_TOKEN}'
    ./unv --db-path ./demo/vault.db env demo            # shows fingerprints, not values
    ./unv --db-path ./demo/vault.db env demo --out rendered.env
    diff <(sort .env) <(grep -v '^#' rendered.env | sort) && echo SAME

    Only a file you ask for with --out receives the real values. The last line prints SAME: the rendered file holds what you imported.

  5. 5. Back up and restore

    A .vaultbak is an encrypted copy under a separate backup password (at least 12 characters), readable by the app and the CLI. Restore it into a different, empty vault to prove it works.

    ./unv --db-path ./demo/vault.db backup export demo.vaultbak --backup-password 'a-long-backup-passphrase'
    mkdir restored
    UNV_PASSWORD='another-passphrase' ./unv --db-path ./restored/vault.db --init \
      backup import demo.vaultbak --backup-password 'a-long-backup-passphrase' --yes
    UNV_PASSWORD='another-passphrase' ./unv --db-path ./restored/vault.db doctor

    doctor checks the database, the salt, file permissions and the audit chain, and ends with Hash chain intact. For a byte-for-byte copy that includes the salt, use unv backup archive instead.

Next: read the guides, or open the app and look at the same project in the desktop interface.