Secrets in apps and functions
Reference vault secrets from an app or a function and read the values in your code.
Add a secret reference
- Open the secret references:
- for an app, open the app and go to Configuration → Secrets;
- for a function, open the function namespace, then the function, and go to its Configuration tab, section Secrets. References belong to the individual function.
- Choose Add Secret. In Add Secret Reference, pick the Vault and the Secret. Only enabled secrets are offered.
- Check the Environment Variable Name. It is filled in from the secret's name in capitals with hyphens turned into underscores, and must be a letter or underscore followed by letters, digits and underscores.
- Choose Add, then Save. The app or function is redeployed with the new references.
Before its pods can start, the workload's identity needs Secrets Reader on the vault; for apps and functions you assign it yourself — see Give a workload access.
Important
A function reads its secrets with the identity of its function namespace, which every function in the namespace shares. Once that identity may read a vault, every function in the namespace can read every secret in it, whether or not the function references it. Keep functions that must not see each other's secrets in separate namespaces or vaults.
Read the values in an app
An app's values are not set as environment variables. The application finds them in the
file /secrets/env.json: a JSON object that maps each name you chose under Environment
Variable Name to the secret's value.
The file is on a read-only volume that lives in memory. Read it at start-up, for example:
const secrets = JSON.parse(require("fs").readFileSync("/secrets/env.json", "utf8"));
const apiKey = secrets.API_KEY;import json
secrets = json.load(open("/secrets/env.json"))
api_key = secrets["API_KEY"]Read the values in a function
A function receives its values as environment variables. When the function starts, its runtime
(Node.js, .NET or Go) reads /secrets/env.json and sets one variable per reference, named
STSH_ followed by the Environment Variable Name in capitals — the reference API_KEY is
read as STSH_API_KEY:
const apiKey = process.env.STSH_API_KEY;var apiKey = Environment.GetEnvironmentVariable("STSH_API_KEY");If the file cannot be read, the function does not start.
When a value changes
The file is written once, when the pod starts. After you change a secret, redeploy or restart the app or function to pick up the new value.