Skip to main content

hivepaas secret

Secrets of an app, or - with --scope env or --scope project - of its environment or its project, which the apps there get unless --no-inheritable. Values are kept hidden, given to an app as ${secrets.KEY} in an env var, or as a file through a setting mount.

hivepaas secret [command]

Aliases: secret, secrets

Flags:

FlagDescription
--scope stringwhose secrets: the app's, its environment's (env) or its project's (project) (default: app)

hivepaas secret ls​

List the secrets, without their values

hivepaas secret ls

Flags:

FlagDescription
--scope stringwhose secrets: the app's, its environment's (env) or its project's (project) (default: app)

hivepaas secret rm​

Remove secrets

hivepaas secret rm KEY...

Flags:

FlagDescription
--scope stringwhose secrets: the app's, its environment's (env) or its project's (project) (default: app)

hivepaas secret set​

Add or change secrets of an app, or with --scope of its environment or project. KEY alone reads the value from stdin, or asks for it at a terminal without showing it: a value on the command line stays in the shell's history. --file takes a file, kept as it is: a keystore, a certificate.

A secret reaches an app as ${secrets.KEY} in an env var, or as a file through a setting mount. One is shared below unless --no-inheritable: an app's with its pull request previews, an environment's or a project's with their apps. A secret changed keeps how it is shared unless told.

hivepaas secret set KEY=VALUE... | KEY --file FILE | KEY [flags]

Examples:

hivepaas secret set STRIPE_KEY
echo -n "$TOKEN" | hivepaas secret set API_TOKEN
hivepaas secret set KEYSTORE --file ./keystore.jks --no-previews
hivepaas secret set DATABASE_URL --scope env -p shop -e production
hivepaas secret set SENTRY_DSN=https://... --scope project --no-inheritable

Flags:

FlagDescription
--file stringthe value is this file's content
--inheritableshared below: with an app's pull request previews, an environment's or a project's apps (default)
--no-inheritablenot shared below
--no-previewsan app's: its pull request previews do not get it
--previewsan app's: its pull request previews get it too (default)
--scope stringwhose secrets: the app's, its environment's (env) or its project's (project) (default: app)

The global flags apply to every command.