Where .env Went Wrong
Summary
The article argues that .env files have become a problematic source of truth for secrets, explaining the risks of conflating configuration with secret delivery. It introduces SecretSpec as a declarative, provider-based approach that separates declaration, storage, and delivery of secrets, and outlines migration steps and practical guidance.