Secretkeep
Sync secrets from your vault into environment variables on every deploy.
Overview
Keep secrets in Secretkeep and reference them by path. At deploy time the platform reads the current values and injects them as environment variables, so nothing sensitive is stored in your repository.
What you can do
- Reference secrets by path in your service config
- Values refreshed on every deploy
- Access logged in your workspace audit log
Set up
- Create a read-only Secretkeep policy for the platform.
- Add the policy token in Integrations → Secretkeep.
- Replace plain values with
secretkeep://references.
Terminal
$ cloud env set DATABASE_URL=secretkeep://prod/db/url --service api