Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Modern Web. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Modern Web or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

How Varlock Fixes .env Vulnerabilities and Secures Your Secrets

40:46
 
Share
 

Manage episode 523594142 series 2927306
Content provided by Modern Web. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Modern Web or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Environment variables and secrets are usually a mess: out of sync .env files, scattered API keys, painful onboarding, and brittle CI configs. In this episode of the Modern Web Podcast, Rob Ocel talks with Varlock co-creators Phil Miller and Theo Ephraim about how Varlock turns .env files into a real schema with types, validation, and documentation, pulls secrets from tools like 1Password and other backends, and centralizes configuration across environments and services. They also dig into protecting secrets in an AI-heavy world by redacting them from logs and responses, preventing accidental leaks from agents, and pushing toward an open env-spec standard so configuration becomes predictable, portable, and actually pleasant to work with.

What you will learn:

- Why traditional .env files and copy paste workflows break down as teams, services, and environments grow.

- How Varlock turns environment variables into a schema with types, validation, documentation, and generated TypeScript.- How to pull secrets from tools like 1Password and other backends without leaving them in plain text or scattering them across dashboards.

- How to manage multiple environments such as development, staging, and production from a single, declarative configuration source.

- How Varlock helps protect secrets in AI and MCP workflows by redacting them from logs and responses and blocking accidental leaks.

- What the env spec standard is and how a common schema format can make configuration more portable across tools, templates, and platforms.

Theo Ephraim on Linkedin: https://www.linkedin.com/in/theo-ephraim/

Phil Miller on Linkedin: https://www.linkedin.com/in/themillman/

Rob Ocel on Linkedin: https://www.linkedin.com/in/robocel/

This Dot Labs Twitter: https://x.com/ThisDotLabs

This Dot Media Twitter: https://x.com/ThisDotMedia

This Dot Labs Instagram: https://www.instagram.com/thisdotlabs/

This Dot Labs Facebook: https://www.facebook.com/thisdot/

This Dot Labs Bluesky: https://bsky.app/profile/thisdotlabs.bsky.social

Sponsored by This Dot Labs: https://ai.thisdot.co/

  continue reading

175 episodes

Artwork
iconShare
 
Manage episode 523594142 series 2927306
Content provided by Modern Web. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Modern Web or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Environment variables and secrets are usually a mess: out of sync .env files, scattered API keys, painful onboarding, and brittle CI configs. In this episode of the Modern Web Podcast, Rob Ocel talks with Varlock co-creators Phil Miller and Theo Ephraim about how Varlock turns .env files into a real schema with types, validation, and documentation, pulls secrets from tools like 1Password and other backends, and centralizes configuration across environments and services. They also dig into protecting secrets in an AI-heavy world by redacting them from logs and responses, preventing accidental leaks from agents, and pushing toward an open env-spec standard so configuration becomes predictable, portable, and actually pleasant to work with.

What you will learn:

- Why traditional .env files and copy paste workflows break down as teams, services, and environments grow.

- How Varlock turns environment variables into a schema with types, validation, documentation, and generated TypeScript.- How to pull secrets from tools like 1Password and other backends without leaving them in plain text or scattering them across dashboards.

- How to manage multiple environments such as development, staging, and production from a single, declarative configuration source.

- How Varlock helps protect secrets in AI and MCP workflows by redacting them from logs and responses and blocking accidental leaks.

- What the env spec standard is and how a common schema format can make configuration more portable across tools, templates, and platforms.

Theo Ephraim on Linkedin: https://www.linkedin.com/in/theo-ephraim/

Phil Miller on Linkedin: https://www.linkedin.com/in/themillman/

Rob Ocel on Linkedin: https://www.linkedin.com/in/robocel/

This Dot Labs Twitter: https://x.com/ThisDotLabs

This Dot Media Twitter: https://x.com/ThisDotMedia

This Dot Labs Instagram: https://www.instagram.com/thisdotlabs/

This Dot Labs Facebook: https://www.facebook.com/thisdot/

This Dot Labs Bluesky: https://bsky.app/profile/thisdotlabs.bsky.social

Sponsored by This Dot Labs: https://ai.thisdot.co/

  continue reading

175 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play