A lightweight Go utility to securely fetch and load environment variables from an encrypted database, designed for backend services that require dynamic configuration without exposing secrets in code or .env files.
- Secure storage of DB credentials and API keys in MongoDB (or any DB)
- Encrypted secret key-based access
- Auto-fetch and injects env variables during application start
- Works well with microservices or distributed systems
- Minimalistic and easy to integrate
- Go (Golang)
- MongoDB
- AES Encryption (CTR or ECB mode)
- dotenv (if
.envfallback is needed)
You can't store DB credentials directly in .env files or hardcode them.
Instead, store them in a DB collection in encrypted format and access them securely at runtime.
- On app start, pass a decryption key as an input flag or env variable.
- The app connects to a base DB using minimal details.
- It decrypts the secrets stored in a collection (like
secrets_config) using the key. - The fetched values are injected into
os.Environ()so that all parts of the app can use them like normal env variables.
os.Getenv("DB_HOST") // returns 127.0.0.1 from secure loader