Profiles
Environment
The session-only envs block, why it is session-only and how glaze handles the values.
An earlier version of Glazier accepted envs on a window and on a pane. It looked like it worked. It did not do what anyone thought it did, so I took it away. This page is the envs reference and the confession in one.
The envs map
session {
name = "daemon-run"
envs = {
EDITOR = "nvim"
ICE_TARGET = "arasaka-mainframe"
}
window {
pane {}
}
}| Attribute | Type | Notes |
|---|---|---|
envs | map(string) | Environment variables for the session. Only the session block accepts envs. A null value is an error. |
Glazier sets each variable with tmux set-environment on the session before it creates any window or pane. Thus every shell that tmux starts for the session gets the variable.
Why session only
tmux has one environment per session and one global environment. It has no window environment and no pane environment. set-environment seeds the session environment, and only a process that tmux starts afterwards gets the new value. A shell that already runs does not change.
An envs block on a window or a pane would therefore do two misleading things. It would apply to the whole session rather than to that window or pane. It would also reach only shells that start later. Rather than support that fiction, the spec rejects envs anywhere but the session. A profile with envs on a window or a pane fails validation:
$ glaze format --validate --profile-path envs-window.glaze
Error: Unsupported argument
on envs-window.glaze line 6, in session:
6: envs = { EDITOR = "nvim" }
An argument named "envs" is not expected here.
the glaze profile contains errors
Per-pane values
Set a value for one pane inline in its commands. The commands run in the shell of the pane, so an export stays in effect for the commands after it.
pane {
commands = [
"export ICE_TARGET=militech-relay",
"EDITOR=vim nvim ./payloads",
]
}See Commands for how the commands reach the shell.
Secrets in logs and errors
An env value can be a secret, for example a token from a variable. Glazier never shows an env value. The --debug log and every error message show the value as <redacted>. The key stays visible.
warning
Treat an env value as visible to other users of the host for a moment. tmux gets each value as a command argument, so another user on the same host can see it with ps while the set-environment command runs. This is documented, not fixed: tmux has no other way to receive the value.
A command can also contain a secret, through a variable or a literal. Glazier shows the text of a command only with --debug, so check that output before you share it.
note
glaze save never exports envs. tmux can report only the whole session environment, which includes every secret in your shell. See save.
The old window and pane envs quietly routed everything onto the session. Nothing broke, nobody complained and it was still wrong, which is the most dangerous kind of feature. If you need a variable in one pane, put it in that pane’s commands where you can see it.