KeyEnvKeyEnv

Azure Pipelines

Load KeyEnv secrets in Azure DevOps pipelines.

Azure Pipelines Integration

Load KeyEnv secrets in your Azure DevOps CI/CD pipelines.

Prerequisites

  • Azure DevOps project with Pipelines enabled
  • KeyEnv service token with read access

Setup

1. Add Your Token

Option A: Pipeline Variable

  1. Edit your pipeline in Azure DevOps
  2. Click Variables
  3. Add KEYENV_TOKEN with your service token
  4. Check Keep this value secret

Option B: Variable Group

  1. Go to Pipelines > Library
  2. Create a new Variable group
  3. Add KEYENV_TOKEN as a secret variable
  4. Link the group to your pipeline

2. Configure azure-pipelines.yml

trigger:
  - main

pool:
  vmImage: 'ubuntu-latest'

variables:
  - group: keyenv-secrets  # If using variable group

steps:
  - task: NodeTool@0
    inputs:
      versionSpec: '20.x'
    displayName: 'Install Node.js'

  - script: curl -fsSL https://keyenv.dev/install.sh | bash
    displayName: 'Install KeyEnv CLI'

  - script: |
      export PATH="$HOME/.keyenv/bin:$PATH"
      keyenv run -p YOUR_PROJECT_ID -e production -- npm ci
    displayName: 'Install dependencies'
    env:
      KEYENV_TOKEN: $(KEYENV_TOKEN)

  - script: |
      export PATH="$HOME/.keyenv/bin:$PATH"
      keyenv run -p YOUR_PROJECT_ID -e production -- npm test
    displayName: 'Run tests'
    env:
      KEYENV_TOKEN: $(KEYENV_TOKEN)

  - script: |
      export PATH="$HOME/.keyenv/bin:$PATH"
      keyenv run -p YOUR_PROJECT_ID -e production -- npm run build
    displayName: 'Build'
    env:
      KEYENV_TOKEN: $(KEYENV_TOKEN)

Environment Mapping

Map branches to KeyEnv environments:

variables:
  ${{ if eq(variables['Build.SourceBranch'], 'refs/heads/main') }}:
    keyenvEnv: 'production'
  ${{ if eq(variables['Build.SourceBranch'], 'refs/heads/staging') }}:
    keyenvEnv: 'staging'
  ${{ else }}:
    keyenvEnv: 'development'

steps:
  - script: |
      export PATH="$HOME/.keyenv/bin:$PATH"
      keyenv run -p YOUR_PROJECT_ID -e $(keyenvEnv) -- npm test
    env:
      KEYENV_TOKEN: $(KEYENV_TOKEN)

Multi-Stage Pipeline

trigger:
  - main
  - staging

stages:
  - stage: Test
    jobs:
      - job: Test
        pool:
          vmImage: 'ubuntu-latest'
        steps:
          - script: curl -fsSL https://keyenv.dev/install.sh | bash
          - script: |
              export PATH="$HOME/.keyenv/bin:$PATH"
              keyenv run -p YOUR_PROJECT_ID -e development -- npm test
            env:
              KEYENV_TOKEN: $(KEYENV_TOKEN)

  - stage: Deploy
    condition: and(succeeded(), eq(variables['Build.SourceBranch'], 'refs/heads/main'))
    jobs:
      - deployment: Production
        environment: 'production'
        strategy:
          runOnce:
            deploy:
              steps:
                - script: curl -fsSL https://keyenv.dev/install.sh | bash
                - script: |
                    export PATH="$HOME/.keyenv/bin:$PATH"
                    keyenv run -p YOUR_PROJECT_ID -e production -- npm run deploy
                  env:
                    KEYENV_TOKEN: $(KEYENV_TOKEN)

Pull Secrets to .env File

steps:
  - script: |
      export PATH="$HOME/.keyenv/bin:$PATH"
      keyenv pull -p YOUR_PROJECT_ID -e production -o .env
    displayName: 'Pull secrets'
    env:
      KEYENV_TOKEN: $(KEYENV_TOKEN)

  - script: |
      source .env
      npm run build
    displayName: 'Build with secrets'

Template Usage

Create a reusable template:

# templates/with-keyenv.yml
parameters:
  - name: projectId
    type: string
  - name: environment
    type: string
  - name: command
    type: string

steps:
  - script: |
      if [ ! -f "$HOME/.keyenv/bin/keyenv" ]; then
        curl -fsSL https://keyenv.dev/install.sh | bash
      fi
    displayName: 'Install KeyEnv CLI'

  - script: |
      export PATH="$HOME/.keyenv/bin:$PATH"
      keyenv run -p ${{ parameters.projectId }} -e ${{ parameters.environment }} -- ${{ parameters.command }}
    displayName: 'Run with KeyEnv'
    env:
      KEYENV_TOKEN: $(KEYENV_TOKEN)

Use the template:

steps:
  - template: templates/with-keyenv.yml
    parameters:
      projectId: 'my-project'
      environment: 'production'
      command: 'npm test'

Docker Builds

steps:
  - script: |
      export PATH="$HOME/.keyenv/bin:$PATH"
      eval $(keyenv export -p YOUR_PROJECT_ID -e production --format shell)

      docker build \
        --build-arg DATABASE_URL=$DATABASE_URL \
        --build-arg API_KEY=$API_KEY \
        -t myapp:$(Build.BuildId) .
    displayName: 'Build Docker image'
    env:
      KEYENV_TOKEN: $(KEYENV_TOKEN)

Azure Container Apps

Deploy to Azure Container Apps with secrets:

steps:
  - script: |
      export PATH="$HOME/.keyenv/bin:$PATH"

      # Export secrets
      keyenv export -p YOUR_PROJECT_ID -e production --format json > secrets.json

      # Update Container App
      az containerapp update \
        --name myapp \
        --resource-group mygroup \
        --set-env-vars $(jq -r '.secrets[] | "\(.key)=\(.value)"' secrets.json | tr '\n' ' ')
    displayName: 'Deploy to Container Apps'
    env:
      KEYENV_TOKEN: $(KEYENV_TOKEN)

Caching

Cache the CLI installation:

variables:
  KEYENV_CACHE_KEY: 'keyenv-cli-v1'

steps:
  - task: Cache@2
    inputs:
      key: '$(KEYENV_CACHE_KEY)'
      path: '$(HOME)/.keyenv'
    displayName: 'Cache KeyEnv CLI'

  - script: |
      if [ ! -f "$HOME/.keyenv/bin/keyenv" ]; then
        curl -fsSL https://keyenv.dev/install.sh | bash
      fi
    displayName: 'Install KeyEnv CLI'

Full Example

trigger:
  - main
  - staging

pool:
  vmImage: 'ubuntu-latest'

variables:
  - group: keyenv-secrets
  - name: keyenvProject
    value: 'your-project-id'

stages:
  - stage: Build
    jobs:
      - job: BuildAndTest
        steps:
          - task: NodeTool@0
            inputs:
              versionSpec: '20.x'

          - task: Cache@2
            inputs:
              key: 'keyenv-cli-v1'
              path: '$(HOME)/.keyenv'

          - script: |
              if [ ! -f "$HOME/.keyenv/bin/keyenv" ]; then
                curl -fsSL https://keyenv.dev/install.sh | bash
              fi
            displayName: 'Install KeyEnv CLI'

          - script: |
              export PATH="$HOME/.keyenv/bin:$PATH"
              keyenv run -p $(keyenvProject) -e development -- npm ci
              keyenv run -p $(keyenvProject) -e development -- npm test
              keyenv run -p $(keyenvProject) -e development -- npm run build
            displayName: 'Build and Test'
            env:
              KEYENV_TOKEN: $(KEYENV_TOKEN)

  - stage: DeployProduction
    condition: and(succeeded(), eq(variables['Build.SourceBranch'], 'refs/heads/main'))
    jobs:
      - deployment: Production
        environment: 'production'
        strategy:
          runOnce:
            deploy:
              steps:
                - script: curl -fsSL https://keyenv.dev/install.sh | bash

                - script: |
                    export PATH="$HOME/.keyenv/bin:$PATH"
                    keyenv run -p $(keyenvProject) -e production -- npm run deploy
                  displayName: 'Deploy'
                  env:
                    KEYENV_TOKEN: $(KEYENV_TOKEN)

Troubleshooting

Variable Not Found

Ensure the variable is marked as secret and passed via env:

- script: echo "Token exists: $([ -n "$KEYENV_TOKEN" ] && echo yes || echo no)"
  env:
    KEYENV_TOKEN: $(KEYENV_TOKEN)

Permission Denied

Check your service token permissions:

- script: |
    export PATH="$HOME/.keyenv/bin:$PATH"
    keyenv whoami
  env:
    KEYENV_TOKEN: $(KEYENV_TOKEN)

On this page