# varlock を Homebrew でインストール

varlock のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

## インストール

```sh
sudo av install brew:varlock
```

追加のインストールコマンド:

### macOS

- Homebrew (100%):

```sh
brew install varlock
```

  証拠: local Homebrew formula metadata

## パッケージ情報

- **パッケージキー:** brew:varlock
- **パッケージマネージャ:** Homebrew
- **バージョン:** 1.16.0
- **ソース概要:** Add declarative schema to .env files using @env-spec decorator comments
- **ホームページ:** <https://varlock.dev>
- **最終更新:** 2026-08-01T21:49:42Z
- **生成日時:** 2026-08-03T19:37:03+00:00

## 実行可能ファイル

- varlock (エイリアス)

## インストール挙動

- Bottle: 利用不可

## バージョンと鮮度

- ページ生成日: 2026-08-03
- マネージャ版: 1.16.0
## プロジェクトの歴史と使われ方

Varlock is a young configuration and secrets tool for `.env`-based workflows. Its project tagline frames the tool around AI-safe `.env` files: schemas are safe for agents and collaborators to read, while actual secrets are resolved separately.

### プロジェクトの歴史

The project is built on `@env-spec`, a DSL that extends normal `.env` syntax with JSDoc-style decorator comments and function-call values. The initial `@env-spec` RFC was proposed on May 13, 2025 by maintainers Phil Millman and Theo Ephraim, describing the goal of richer validation, type coercion, sensitive-value handling, and dynamic loading while keeping the familiar `.env` format.

### 採用の歴史

Varlock targets the pain point left by `.env.example`: example files are safe to commit but often drift from real runtime requirements. Varlock instead promotes a committed `.env.schema` as a single source of truth, with local or environment-specific `.env.*` files supplying values.

### 使われ方

Typical usage starts with `varlock init`, which scans existing `.env` files and creates a root `.env.schema`. Users then run `varlock load` to validate and inspect resolved environment variables or `varlock run -- <command>` to execute a process with resolved values. The tool also ships as a standalone binary, Docker image, editor support, and plugins for secret backends such as 1Password, AWS, Azure, Google Secret Manager, HashiCorp Vault, and others.

### パッケージ好きにとっての重要性

For package users, Varlock is notable as an attempt to standardize metadata around environment variables without forcing a new YAML, JSON, or TypeScript schema file. It is especially tuned for modern AI-assisted development, where agents need configuration context but should not be handed plaintext secrets.

### タイムライン

- 2025-05-13: Initial `@env-spec` RFC proposed.
- 2026: Repository documents Varlock as a CLI, Docker image, VS Code extension ecosystem, and plugin host for multiple secret backends.

### Related projects

- DMNO is cited by the maintainers as the predecessor whose lessons informed Varlock.
- `@env-spec` is the underlying specification and parser family used by Varlock.

### ソース

- Initial @env-spec RFC: https://github.com/dmno-dev/varlock/discussions/17
- Official @env-spec overview: https://varlock.dev/env-spec/overview/
- Official GitHub repository: https://github.com/dmno-dev/varlock
- Official installation guide: https://varlock.dev/getting-started/installation/


## セキュリティノート

varlock に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: .env.schema

## Credential files

- Unix: .env.local, .env.*

## Combined YAML source

View the package source record on GitHub. [combined/varlock.yml](https://github.com/mxcl/pkgdb/blob/main/combined/varlock.yml)


## ソース

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- cross-ecosystem install command graph
