Skip to main content

Env vars and secrets

An app gets its configuration from env vars, and its passwords and keys from secrets. Both are set in the app's configuration, or once for a whole project or environment.

Env vars​

In the app's Env Variables, env vars come in three kinds:

KindFor
Runtime Env VariablesThe app's containers, while they run.
Build Time Env VariablesThe image's build, for an app built from a Git repository.
Shared Runtime Env VariablesThe app's containers, and the other apps of its environment, which can refer to them.

A change takes effect on the app's next deployment. Re-deploy applies it without changing anything else.

From the project and the environment​

Env vars that many apps need, such as a log level or a region, go in the project's Env Variables: for the whole project, or for one environment.

An app gets them all, and shows them as Inherited on its own page. Where an app sets a variable of the same name, its own value wins.

Referring to other values​

An env var's value can refer to other values:

ReferenceIs
${NAME}another env var of the app
${secrets.NAME}a secret of the app
${<app key>.NAME}a shared variable of another app of the same environment
LOG_PREFIX=${HIVEPAAS_APP_NAME}-worker
API_TOKEN=${secrets.API_TOKEN}
CACHE_URL=redis://${cache.HIVEPAAS_HOST}:${cache.HIVEPAAS_PORT}/0

References to other apps are the way to connect apps: they follow the other app when it moves or changes, where a hard-coded address does not. Link to another app writes them for you; see Databases. Suggest Env writes those a database's own image reads to set itself up; see Run one from its image.

Variables HivePaaS sets​

HivePaaS gives every app variables of its own:

VariableHolds
HIVEPAAS_APP_NAMEthe app's name
HIVEPAAS_APP_IDthe app's ID
HIVEPAAS_ENVits environment
HIVEPAAS_HOSTits host name on its environment's network, its key
HIVEPAAS_PORTits port
HIVEPAAS_DOMAINits domain
HIVEPAAS_APP_URLwhere it answers from outside, such as https://shop.example.com

A database also shares its name, user and password.

Secrets​

A secret is a value nobody should read in the dashboard: a password, an API key, a private key. In the app's Secrets, create one with:

  • Name, such as STRIPE_KEY;
  • Value Type: Text, or Binary for a file, such as a keystore;
  • Value, up to 500 KB;
  • Available in Previews, for the app's pull request previews to get it too.

A secret reaches the app two ways:

  • as an env var, from a reference: STRIPE_KEY=${secrets.STRIPE_KEY}. Only a secret of 10 KB or less can be referred to;
  • as a file, through a setting mount.

Secrets and env vars​

  • Secrets stay hidden. Once saved, a secret's value is shown only to a user who may reveal secrets, with Reveal Secret.
  • Secrets are kept out of logs. HivePaaS filters their values out of the logs it shows; env vars' values are not.

A project's Secrets serve all its apps, like its env vars.