KeyEnvKeyEnv

CI/CD Integration

Integrate KeyEnv with your CI/CD pipeline.

CI/CD Integration

This guide shows how to integrate KeyEnv with popular CI/CD platforms.

Prerequisites

  1. A KeyEnv project with secrets configured
  2. A service token with access to the appropriate environment

Creating a Service Token

  1. Go to Project Settings → Service Tokens
  2. Click Create Token
  3. Name it after your CI/CD platform (e.g., "GitHub Actions - Production")
  4. Select the environment (e.g., production)
  5. Copy the token

GitHub Actions

Add your service token to GitHub Secrets, then use it in your workflow:

name: Deploy

on:
  push:
    branches: [main]

jobs:
  deploy:
    runs-on: ubuntu-latest

    steps:
      - uses: actions/checkout@v4

      - name: Install KeyEnv
        run: curl -fsSL https://keyenv.dev/install.sh | bash

      - name: Pull secrets
        env:
          KEYENV_TOKEN: ${{ secrets.KEYENV_TOKEN }}
        run: keyenv pull -e production

      - name: Deploy
        run: |
          # Your deployment commands
          # Secrets are available in .env

Alternative: Inject at Runtime

- name: Run with secrets
  env:
    KEYENV_TOKEN: ${{ secrets.KEYENV_TOKEN }}
  run: keyenv run -e production -- npm run deploy

GitLab CI

Add the token as a CI/CD variable, then use it:

deploy:
  stage: deploy
  image: ubuntu:latest
  before_script:
    - apt-get update && apt-get install -y curl
    - curl -fsSL https://keyenv.dev/install.sh | bash
    - export PATH="$HOME/.keyenv/bin:$PATH"
  script:
    - keyenv pull -e production
    - ./deploy.sh
  variables:
    KEYENV_TOKEN: $KEYENV_TOKEN
  only:
    - main

CircleCI

Use the official KeyEnv orb for the easiest integration:

version: 2.1

orbs:
  keyenv: keyenv/[email protected]

jobs:
  deploy:
    docker:
      - image: cimg/base:stable
    steps:
      - checkout
      - keyenv/load:
          environment: production
      - run:
          name: Deploy
          command: ./deploy.sh

workflows:
  deploy:
    jobs:
      - deploy:
          filters:
            branches:
              only: main

For more detailed examples and options, see the CircleCI Integration Guide.

Secret Scanning

KeyEnv can scan your codebase for hardcoded secrets before they reach production. Add secret scanning to your CI/CD pipeline to catch leaks early.

GitHub Actions

Use the official scan action:

name: Security

on: [push, pull_request]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Scan for secrets
        uses: keyenv/scan-action@v1
        with:
          severity: high

Other CI/CD Platforms

Use the CLI scanner:

# Install KeyEnv
curl -fsSL https://keyenv.dev/install.sh | bash

# Scan for secrets
keyenv scan --severity high

The scanner detects 149+ secret patterns including AWS keys, GitHub tokens, Stripe keys, database passwords, and more.

Enable the Scan for secrets toggle in the KeyEnv dashboard integrations page to automatically add scanning to your generated workflow configurations.

For complete scanning documentation, see the Secret Scanner Action.

Best Practices

  1. Scan for hardcoded secrets - Add keyenv scan or the scan action to catch leaks before they're merged
  2. Use environment-specific tokens - Create separate tokens for staging and production
  3. Limit token scope - Only grant access to the environments needed
  4. Don't log secrets - Avoid echoing secret values in CI logs
  5. Use keyenv run - When possible, inject secrets at runtime instead of writing to disk

Never commit service tokens to your repository. Always use your CI/CD platform's secret management.

On this page