Utilo

.env Converter

Convert environment variables between .env, JSON, YAML, Kubernetes Secret and ConfigMap, docker env-file and shell exports. Compare two env files to find missing, extra and empty variables.

What this .env converter does

Configuration moves between formats all the time: a local .env file becomes a Kubernetes Secret, a JSON config becomes environment variables in CI, a YAML file feeds a Helm chart. This converter reads environment variables from .env, JSON, YAML, Kubernetes Secret or ConfigMap manifests, docker env-files or shell export lines, and writes them to any of those formats. A second mode compares two env files and lists variables that are missing, extra, empty or duplicated, which is exactly what you need before a deploy fails because someone forgot to add a key to production.

How to use it

  1. In Convert mode, paste your variables and choose the input format, or leave it on auto-detect.
  2. Choose the output format. For Kubernetes, set the resource name; Secret values are Base64-encoded automatically.
  3. Copy or download the result.
  4. In Compare mode, paste your real .env into A and .env.example or another environment into B.
  5. Review the lists: missing in A, extra in A, empty values and duplicate keys.

Format details

  • .env: supports comments, export prefixes, single and double quotes, escaped newlines in double quotes and inline comments after unquoted values.
  • JSON / YAML: a flat object of keys to values. Nested objects are flattened with __ (e.g. DB__HOST) and numbers or booleans become strings.
  • Kubernetes Secret: uses data with Base64 values; incoming manifests with stringData are also understood.
  • ConfigMap: plain string values under data.
  • docker env-file: KEY=value with no quote processing, exactly as docker run --env-file reads it.
  • Shell: export KEY='value' lines with safe single-quote escaping, ready to source.

Tips

  • Base64 is encoding, not encryption. Anyone who can read a Kubernetes Secret manifest can read its values; use Sealed Secrets, SOPS or an external secret manager for git.
  • Keep .env.example in version control with empty values and use the compare mode in code review.
  • Keys are case-sensitive on Linux; Api_Key and API_KEY are different variables.

Frequently asked questions

Are my secrets uploaded?

No. Parsing and conversion happen in your browser and nothing is stored or transmitted.

Why are duplicate keys flagged?

Most loaders keep the last value silently, which hides mistakes. The tool shows duplicates so you can decide which one wins.

Can it read .env files with multi-line values?

Yes, inside double quotes. Multi-line values are written back correctly in each output format.

What does "empty values" mean in compare mode?

Keys that exist in your file A but have no value, which usually means someone copied the template and forgot to fill it in.

Yes. All processing happens directly in your browser using JavaScript, Web Workers and Web APIs. Nothing you type, paste or upload is sent to our servers.