CI/CD Integration
Integrate KeyEnv with your CI/CD pipeline.
CI/CD Integration
This guide shows how to integrate KeyEnv with popular CI/CD platforms.
Prerequisites
- A KeyEnv project with secrets configured
- A service token with access to the appropriate environment
Creating a Service Token
- Go to Project Settings → Service Tokens
- Click Create Token
- Name it after your CI/CD platform (e.g., "GitHub Actions - Production")
- Select the environment (e.g.,
production) - Copy the token
GitHub Actions
Add your service token to GitHub Secrets, then use it in your workflow:
name: Deploy
on:
push:
branches: [main]
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install KeyEnv
run: curl -fsSL https://keyenv.dev/install.sh | bash
- name: Pull secrets
env:
KEYENV_TOKEN: ${{ secrets.KEYENV_TOKEN }}
run: keyenv pull -e production
- name: Deploy
run: |
# Your deployment commands
# Secrets are available in .envAlternative: Inject at Runtime
- name: Run with secrets
env:
KEYENV_TOKEN: ${{ secrets.KEYENV_TOKEN }}
run: keyenv run -e production -- npm run deployGitLab CI
Add the token as a CI/CD variable, then use it:
deploy:
stage: deploy
image: ubuntu:latest
before_script:
- apt-get update && apt-get install -y curl
- curl -fsSL https://keyenv.dev/install.sh | bash
- export PATH="$HOME/.keyenv/bin:$PATH"
script:
- keyenv pull -e production
- ./deploy.sh
variables:
KEYENV_TOKEN: $KEYENV_TOKEN
only:
- mainCircleCI
Use the official KeyEnv orb for the easiest integration:
version: 2.1
orbs:
keyenv: keyenv/[email protected]
jobs:
deploy:
docker:
- image: cimg/base:stable
steps:
- checkout
- keyenv/load:
environment: production
- run:
name: Deploy
command: ./deploy.sh
workflows:
deploy:
jobs:
- deploy:
filters:
branches:
only: mainFor more detailed examples and options, see the CircleCI Integration Guide.
Secret Scanning
KeyEnv can scan your codebase for hardcoded secrets before they reach production. Add secret scanning to your CI/CD pipeline to catch leaks early.
GitHub Actions
Use the official scan action:
name: Security
on: [push, pull_request]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Scan for secrets
uses: keyenv/scan-action@v1
with:
severity: highOther CI/CD Platforms
Use the CLI scanner:
# Install KeyEnv
curl -fsSL https://keyenv.dev/install.sh | bash
# Scan for secrets
keyenv scan --severity highThe scanner detects 149+ secret patterns including AWS keys, GitHub tokens, Stripe keys, database passwords, and more.
Enable the Scan for secrets toggle in the KeyEnv dashboard integrations page to automatically add scanning to your generated workflow configurations.
For complete scanning documentation, see the Secret Scanner Action.
Best Practices
- Scan for hardcoded secrets - Add
keyenv scanor the scan action to catch leaks before they're merged - Use environment-specific tokens - Create separate tokens for staging and production
- Limit token scope - Only grant access to the environments needed
- Don't log secrets - Avoid echoing secret values in CI logs
- Use
keyenv run- When possible, inject secrets at runtime instead of writing to disk
Never commit service tokens to your repository. Always use your CI/CD platform's secret management.