keepassxc-cli, secret-tool (GNOME Keyring), pass, gpg, Vaultwarden’s CLI, or a script that cats a tmpfs env file. The helper prints KEY=VALUE lines on stdout; Mibyan applies them through the same orchestrator as Bitwarden and 1Password, so you can enable any combination of sources simultaneously.
How it works
- You configure a helper command in
config.yaml(never in.env— the command is configuration,.envholds values). - At startup, after
.envloads, Mibyan runs the helper ONCE via/bin/sh -cand parses its stdout as a dotenv blob. - The parsed keys flow through the standard precedence ladder:
.env/shell win unlessoverride_existing: true; mapped sources beat this bulk source on contested vars; first claim wins.
Config
Security model
- The helper command string is YOUR configuration — same trust level as the
.envfile you control. - Output is hard-capped at 1 MiB; a runaway helper can’t wedge startup (process group killed on timeout).
- The helper’s stderr is discarded — vault CLI diagnostics can carry secret material, so they never reach Mibyan’ output. Failures log structured fields only (exit code / signal / errno), never the command string.
- Whitespace-only values are treated as “no value” — a placeholder entry never flows into an Authorization header.
- POSIX-only (needs
/bin/sh). On Windows the source reports itself unconfigured and startup continues.
Failure modes
Startup is never blocked. Errors print one line plus a→ remediation hint:

