Getting Started
What is bwsf?
bwsf is a CLI tool that uses Bitwarden to manage project files such as .env* and Terraform *.tfvars / *.tfvars.json securely.
Instead of sharing secrets through insecure channels like email or Slack, bwsf lets you store them in your Bitwarden vault and sync them across your team.
Prerequisites
Before using bwsf, make sure you have:
- Bitwarden Account - Either Bitwarden Cloud or a self-hosted Bitwarden server
- Bitwarden CLI (
bw) - The official Bitwarden command-line tool
Installing Bitwarden CLI
Follow the official Bitwarden CLI installation guide to install the bw command on your machine.
Verify the installation:
bw --version
How bwsf Works
bwsf stores managed files as Note items in a Bitwarden folder (default name: dotenvs). Here's how the structure looks:
Bitwarden Vault
└── dotenvs/ # Default folder for bwsf (configurable)
├── my-web-app # Project name = current directory name
│ ├── .env
│ ├── .env.staging
│ ├── .env.production
│ └── terraform.tfvars
└── another-project
└── .env
::: info
By default the folder name is dotenvs. You can change it with bwsf setup --folder <name>. Changing the name does not move existing notes.
:::
Initial Setup
After installing bwsf, run the setup command:
bwsf setup
This will configure:
- Your Bitwarden server URL (for self-hosted instances)
- Your Bitwarden account credentials
Check the saved values any time with:
bwsf config show
Next Steps
- Install bwsf - Installation instructions for your platform
- Commands - Learn all available commands