# CI/CD Integration

Integrate KeyEnv with your CI/CD pipeline.

Source: https://keyenv.dev/docs/guides/ci-cd/

This guide shows how to integrate KeyEnv with popular CI/CD platforms.

## Prerequisites

1. A KeyEnv project with secrets configured
2. A service token with access to the appropriate environment

## Creating a Service Token

1. Go to **Project Settings** → **Service Tokens**
2. Click **Create Token**
3. Name it after your CI/CD platform (e.g., "GitHub Actions - Production")
4. Select the environment (e.g., `production`)
5. Copy the token

## GitHub Actions

Add your service token to GitHub Secrets, then use it in your workflow:

```yaml
name: Deploy

on:
  push:
    branches: [main]

jobs:
  deploy:
    runs-on: ubuntu-latest

    steps:
      - uses: actions/checkout@v4

      - name: Install KeyEnv
        run: curl -fsSL https://keyenv.dev/install.sh | bash

      - name: Pull secrets
        env:
          KEYENV_TOKEN: ${{ secrets.KEYENV_TOKEN }}
        run: keyenv pull -e production

      - name: Deploy
        run: |
          # Your deployment commands
          # Secrets are available in .env
```

### Alternative: Inject at Runtime

```yaml
- name: Run with secrets
  env:
    KEYENV_TOKEN: ${{ secrets.KEYENV_TOKEN }}
  run: keyenv run -e production -- npm run deploy
```

## GitLab CI

Add the token as a CI/CD variable, then use it:

```yaml
deploy:
  stage: deploy
  image: ubuntu:latest
  before_script:
    - apt-get update && apt-get install -y curl
    - curl -fsSL https://keyenv.dev/install.sh | bash
    - export PATH="$HOME/.keyenv/bin:$PATH"
  script:
    - keyenv pull -e production
    - ./deploy.sh
  variables:
    KEYENV_TOKEN: $KEYENV_TOKEN
  only:
    - main
```

## CircleCI

Use the official KeyEnv orb for the easiest integration:

```yaml
version: 2.1

orbs:
  keyenv: keyenv/secrets@1.0

jobs:
  deploy:
    docker:
      - image: cimg/base:stable
    steps:
      - checkout
      - keyenv/load:
          environment: production
      - run:
          name: Deploy
          command: ./deploy.sh

workflows:
  deploy:
    jobs:
      - deploy:
          filters:
            branches:
              only: main
```

For more detailed examples and options, see the [CircleCI Integration Guide](/docs/guides/circleci).

## Secret Scanning

KeyEnv can scan your codebase for hardcoded secrets before they reach production. Add secret scanning to your CI/CD pipeline to catch leaks early.

### GitHub Actions

Use the official scan action:

```yaml
name: Security

on: [push, pull_request]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Scan for secrets
        uses: keyenv/scan-action@v1
        with:
          severity: high
```

### Other CI/CD Platforms

Use the CLI scanner:

```bash
# Install KeyEnv
curl -fsSL https://keyenv.dev/install.sh | bash

# Scan for secrets
keyenv scan --severity high
```

The scanner detects 149+ secret patterns including AWS keys, GitHub tokens, Stripe keys, database passwords, and more.

> **Tip**
>
> Enable the **Scan for secrets** toggle in the KeyEnv dashboard integrations page to automatically add scanning to your generated workflow configurations.

For complete scanning documentation, see the [Secret Scanner Action](/docs/sdks/scan-action).

## Best Practices

1. **Scan for hardcoded secrets** - Add `keyenv scan` or the scan action to catch leaks before they're merged
2. **Use environment-specific tokens** - Create separate tokens for staging and production
3. **Limit token scope** - Only grant access to the environments needed
4. **Don't log secrets** - Avoid echoing secret values in CI logs
5. **Use `keyenv run`** - When possible, inject secrets at runtime instead of writing to disk

> **Warning**
>
> Never commit service tokens to your repository. Always use your CI/CD platform's secret management.
