capy run has you covered. It decrypts .env in memory and spawns your command with the plaintext values injected as environment variables. It works with anything that reads env vars - PHP, Elixir, Java, .NET, Deno, Bun, static binaries, shell scripts.
The pattern
- Reads the local
.envfile. - Decrypts every
capy:…snippet using your project key. - Spawns the child process with the decrypted values in its environment.
- Forwards signals (
SIGINT,SIGTERM,SIGHUP) and exits with the child’s exit code.
Examples
In containers
capy run works as a container entrypoint when SECRETS_BLOB and PROJECT_KEY are both set. In that mode it decrypts the blob instead of reading .env and contacts the Capy service at startup. The pair must be complete; a half-configured pair exits with an error. See Deploying for target and token setup.
What’s next
Running your app
Signals, exit codes, and env precedence in detail.