Pudu programming language
Menu
Package

@chrismichaelps / pudu-lang-environment

Environment files for Pudu: load .env variables safely with layered files, discovery, expansion, typed reads, and secrets kept out of every message

0.1.0Apache-2.01

InstallClose

← All contributions

feat(loader): publish the initial environment package #2

merged

@chrismichaelps wrote on 2026-10-07

Closes #1

Behaviour

  • The .env format: blank and comment lines (indented ones too), keys, single- and double-quoted values, values spanning lines, escaped quotes and backslashes, inline comments, export syntax, trimming, and CRLF lines. A quote that never closes refuses the file even in a lenient load.
  • Expansion of $NAME, ${NAME}, ${NAME:-default}, and ${NAME-default}, once per value, from earlier assignments and then the process environment; without overwriting, the process values the load keeps are what expansions see.
  • Given files, upward probing, and the environment cascade (.env, .env.local, .env.<name>, .env.<name>.local, named by PUDU_ENV or PROFILE), with names that could leave the directory refused.
  • Strict and lenient loading, overwrite rules, options validated as a whole, UTF-8, Latin-1, and UTF-16 decoding with byte-order marks, and text or byte sources.
  • Variables: the loaded values settled over the process environment without writing it, with typed reads, secret, require, apply for child processes, and describe.
  • Settings records bound by derives Binding.Bind (@env, @default), rendered by derives Binding.Redacted (@secret), and checked by a pudu-lang-validator validator.
  • No problem, description, or rendering carries a value read from a file.
  • Settings layered over Std.App.Config with config.withVariables(&variables); ASCII and UTF-32 decoding beside UTF-8, Latin-1, and UTF-16.
  • A compiler fault met while writing the derive is reported as chrismichaelps/pudu-lang#457 and worked around.

Pre-release audit

  • Feature parity was checked item by item against the full design: loading and reading, the fluent chain, strictness, encodings, trimming, overwriting, probing, export syntax, inline comments, expansion, the environment cascade, stream sources, typed reads, and the configuration provider, which became Configuration.
  • Fixed: Redacted rendered an unmarked Secret field, or one inside an Option, with its raw value, because show over Std.App.Secret prints it. Every Secret now renders as [REDACTED].
  • Fixed: a Text source starting with a byte-order mark kept it in its first key.
  • Confirmed sound: non-ASCII keys and values, quotes and escapes across lines, cascade names that try to leave their directory, and expansion under both overwrite rules.

Verification

On the published Pudu 0.1.3 archive:

  • pudu check, pudu fmt --check, and pudu lint are clean over src, test, tools, and examples.
  • pudu test test: 20 suites, 376 assertions.
  • Every program under examples/ answers 0.
  • pudu run tools/Mutate.pudu --domain --suites test/PuduLangEnvironment/Domain --threshold 100: 131 killed, 0 survived, score 100%.
  • test/Package/VaultTest confirms the vault mirrors src/ with signatures, Grill Logs, and backlinks.

Read and reply on GitHub ↗