Java

Updated

dev.kryptic:daemon-client fetches your project's secrets and exposes them as system properties (the JVM cannot modify its own process environment). Zero dependencies, Java 17+. Outside development it is a no-op, and it never throws.

Spring Boot apps can take dev.kryptic:daemon-client-spring-boot instead and put @EnableKryptic on the application class. That calls Kryptic.fetch() and adds a kryptic property source to the Spring Environment.

Source: github.com/dev-kryptic/Kryptic.Java.

Install

<dependency>
  <groupId>dev.kryptic</groupId>
  <artifactId>daemon-client</artifactId>
  <version>1.0.1</version>
</dependency>

Spring Boot:

<dependency>
  <groupId>dev.kryptic</groupId>
  <artifactId>daemon-client-spring-boot</artifactId>
  <version>1.0.1</version>
</dependency>

Use

import dev.kryptic.Kryptic;

public static void main(String[] args) {
    Kryptic.inject();   // before the framework boots

    var dbUrl = System.getProperty("DATABASE_URL");
}

For frameworks that want a map instead of system properties, use Kryptic.fetch():

Map<String, String> secrets = Kryptic.fetch();

Spring Boot:

import dev.kryptic.spring.EnableKryptic;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.boot.SpringApplication;

@SpringBootApplication
@EnableKryptic
public class Application {
    public static void main(String[] args) {
        SpringApplication.run(Application.class, args);
    }
}

@Value("${DATABASE_URL}") and environment.getProperty("DATABASE_URL") then resolve from the daemon during development.

Behavior

  • No-op when SPRING_PROFILES_ACTIVE/APP_ENV/ENVIRONMENT/ENV indicates production or staging, or when KRYPTIC_DISABLED=true.
  • Finds kryptic.json by walking up from the working directory.
  • Never overwrites system properties or environment variables that are already set.
  • macOS/Linux via unix domain socket channels, Windows via named pipe.

Environment variables (or system properties with the same names) override everything: KRYPTIC_PROJECT_ID, KRYPTIC_ENV, KRYPTIC_SOCKET_PATH, KRYPTIC_TIMEOUT_MS, KRYPTIC_DISABLED, KRYPTIC_SILENT.