Skip to content
Stackship documentation Svenska

SecretsUsers

Secrets in apps and functions

Reference vault secrets from an app or a function and read the values in your code.

Add a secret reference

  1. Open the secret references:
    • for an app, open the app and go to Configuration → Secrets;
    • for a function, open the function namespace, then the function, and go to its Configuration tab, section Secrets. References belong to the individual function.
  2. Choose Add Secret. In Add Secret Reference, pick the Vault and the Secret. Only enabled secrets are offered.
  3. Check the Environment Variable Name. It is filled in from the secret's name in capitals with hyphens turned into underscores, and must be a letter or underscore followed by letters, digits and underscores.
  4. Choose Add, then Save. The app or function is redeployed with the new references.

Before its pods can start, the workload's identity needs Secrets Reader on the vault; for apps and functions you assign it yourself — see Give a workload access.

Important

A function reads its secrets with the identity of its function namespace, which every function in the namespace shares. Once that identity may read a vault, every function in the namespace can read every secret in it, whether or not the function references it. Keep functions that must not see each other's secrets in separate namespaces or vaults.

Read the values in an app

An app's values are not set as environment variables. The application finds them in the file /secrets/env.json: a JSON object that maps each name you chose under Environment Variable Name to the secret's value.

The file is on a read-only volume that lives in memory. Read it at start-up, for example:

javascript
const secrets = JSON.parse(require("fs").readFileSync("/secrets/env.json", "utf8"));
const apiKey = secrets.API_KEY;
python
import json
secrets = json.load(open("/secrets/env.json"))
api_key = secrets["API_KEY"]

Read the values in a function

A function receives its values as environment variables. When the function starts, its runtime (Node.js, .NET or Go) reads /secrets/env.json and sets one variable per reference, named STSH_ followed by the Environment Variable Name in capitals — the reference API_KEY is read as STSH_API_KEY:

javascript
const apiKey = process.env.STSH_API_KEY;
csharp
var apiKey = Environment.GetEnvironmentVariable("STSH_API_KEY");

If the file cannot be read, the function does not start.

When a value changes

The file is written once, when the pod starts. After you change a secret, redeploy or restart the app or function to pick up the new value.