Azure Pipelines
Load KeyEnv secrets in Azure DevOps pipelines.
Azure Pipelines Integration
Load KeyEnv secrets in your Azure DevOps CI/CD pipelines.
Prerequisites
- Azure DevOps project with Pipelines enabled
- KeyEnv service token with read access
Setup
1. Add Your Token
Option A: Pipeline Variable
- Edit your pipeline in Azure DevOps
- Click Variables
- Add
KEYENV_TOKENwith your service token - Check Keep this value secret
Option B: Variable Group
- Go to Pipelines > Library
- Create a new Variable group
- Add
KEYENV_TOKENas a secret variable - Link the group to your pipeline
2. Configure azure-pipelines.yml
trigger:
- main
pool:
vmImage: 'ubuntu-latest'
variables:
- group: keyenv-secrets # If using variable group
steps:
- task: NodeTool@0
inputs:
versionSpec: '20.x'
displayName: 'Install Node.js'
- script: curl -fsSL https://keyenv.dev/install.sh | bash
displayName: 'Install KeyEnv CLI'
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv run -p YOUR_PROJECT_ID -e production -- npm ci
displayName: 'Install dependencies'
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv run -p YOUR_PROJECT_ID -e production -- npm test
displayName: 'Run tests'
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv run -p YOUR_PROJECT_ID -e production -- npm run build
displayName: 'Build'
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)Environment Mapping
Map branches to KeyEnv environments:
variables:
${{ if eq(variables['Build.SourceBranch'], 'refs/heads/main') }}:
keyenvEnv: 'production'
${{ if eq(variables['Build.SourceBranch'], 'refs/heads/staging') }}:
keyenvEnv: 'staging'
${{ else }}:
keyenvEnv: 'development'
steps:
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv run -p YOUR_PROJECT_ID -e $(keyenvEnv) -- npm test
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)Multi-Stage Pipeline
trigger:
- main
- staging
stages:
- stage: Test
jobs:
- job: Test
pool:
vmImage: 'ubuntu-latest'
steps:
- script: curl -fsSL https://keyenv.dev/install.sh | bash
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv run -p YOUR_PROJECT_ID -e development -- npm test
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)
- stage: Deploy
condition: and(succeeded(), eq(variables['Build.SourceBranch'], 'refs/heads/main'))
jobs:
- deployment: Production
environment: 'production'
strategy:
runOnce:
deploy:
steps:
- script: curl -fsSL https://keyenv.dev/install.sh | bash
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv run -p YOUR_PROJECT_ID -e production -- npm run deploy
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)Pull Secrets to .env File
steps:
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv pull -p YOUR_PROJECT_ID -e production -o .env
displayName: 'Pull secrets'
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)
- script: |
source .env
npm run build
displayName: 'Build with secrets'Template Usage
Create a reusable template:
# templates/with-keyenv.yml
parameters:
- name: projectId
type: string
- name: environment
type: string
- name: command
type: string
steps:
- script: |
if [ ! -f "$HOME/.keyenv/bin/keyenv" ]; then
curl -fsSL https://keyenv.dev/install.sh | bash
fi
displayName: 'Install KeyEnv CLI'
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv run -p ${{ parameters.projectId }} -e ${{ parameters.environment }} -- ${{ parameters.command }}
displayName: 'Run with KeyEnv'
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)Use the template:
steps:
- template: templates/with-keyenv.yml
parameters:
projectId: 'my-project'
environment: 'production'
command: 'npm test'Docker Builds
steps:
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
eval $(keyenv export -p YOUR_PROJECT_ID -e production --format shell)
docker build \
--build-arg DATABASE_URL=$DATABASE_URL \
--build-arg API_KEY=$API_KEY \
-t myapp:$(Build.BuildId) .
displayName: 'Build Docker image'
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)Azure Container Apps
Deploy to Azure Container Apps with secrets:
steps:
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
# Export secrets
keyenv export -p YOUR_PROJECT_ID -e production --format json > secrets.json
# Update Container App
az containerapp update \
--name myapp \
--resource-group mygroup \
--set-env-vars $(jq -r '.secrets[] | "\(.key)=\(.value)"' secrets.json | tr '\n' ' ')
displayName: 'Deploy to Container Apps'
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)Caching
Cache the CLI installation:
variables:
KEYENV_CACHE_KEY: 'keyenv-cli-v1'
steps:
- task: Cache@2
inputs:
key: '$(KEYENV_CACHE_KEY)'
path: '$(HOME)/.keyenv'
displayName: 'Cache KeyEnv CLI'
- script: |
if [ ! -f "$HOME/.keyenv/bin/keyenv" ]; then
curl -fsSL https://keyenv.dev/install.sh | bash
fi
displayName: 'Install KeyEnv CLI'Full Example
trigger:
- main
- staging
pool:
vmImage: 'ubuntu-latest'
variables:
- group: keyenv-secrets
- name: keyenvProject
value: 'your-project-id'
stages:
- stage: Build
jobs:
- job: BuildAndTest
steps:
- task: NodeTool@0
inputs:
versionSpec: '20.x'
- task: Cache@2
inputs:
key: 'keyenv-cli-v1'
path: '$(HOME)/.keyenv'
- script: |
if [ ! -f "$HOME/.keyenv/bin/keyenv" ]; then
curl -fsSL https://keyenv.dev/install.sh | bash
fi
displayName: 'Install KeyEnv CLI'
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv run -p $(keyenvProject) -e development -- npm ci
keyenv run -p $(keyenvProject) -e development -- npm test
keyenv run -p $(keyenvProject) -e development -- npm run build
displayName: 'Build and Test'
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)
- stage: DeployProduction
condition: and(succeeded(), eq(variables['Build.SourceBranch'], 'refs/heads/main'))
jobs:
- deployment: Production
environment: 'production'
strategy:
runOnce:
deploy:
steps:
- script: curl -fsSL https://keyenv.dev/install.sh | bash
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv run -p $(keyenvProject) -e production -- npm run deploy
displayName: 'Deploy'
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)Troubleshooting
Variable Not Found
Ensure the variable is marked as secret and passed via env:
- script: echo "Token exists: $([ -n "$KEYENV_TOKEN" ] && echo yes || echo no)"
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)Permission Denied
Check your service token permissions:
- script: |
export PATH="$HOME/.keyenv/bin:$PATH"
keyenv whoami
env:
KEYENV_TOKEN: $(KEYENV_TOKEN)