rebase secret
Store workspace secrets to reference from secrets= on functions, models, and apps.
Synopsis
rebase secret create <name> KEY=value [KEY=value ...]
rebase secret create <name> KEY=-
rebase secret create <name> --from-dotenv .env
rebase secret list [--json]
rebase secret delete <name> [--json]Subcommands
| Subcommand | Arguments | Description |
|---|---|---|
create | <name> [KEY=value]... | Create a secret bundle: a named set of environment variables. |
delete | <name> | Delete a secret bundle and all of its keys. |
list | none | List secret bundles and their keys, never their values. |
Behavior
Values are written to Secret Manager and never stored or shown by Rebase. Attach a bundle
in code with secrets=[rebase.Secret.from_name("<name>")]; every key becomes an
environment variable in the container.
KEY=- reads that one value from stdin, so it stays out of your shell history. Only one
key per command may read from stdin. With --from-dotenv, pairs given on the command line
override the same keys from the file. create refuses a name that already exists unless
you pass --force.
printf '%s' "$SNOWFLAKE_PASSWORD" | rebase secret create snowflake SNOWFLAKE_USER=me SNOWFLAKE_PASSWORD=-See Credentials for how a bundle is used from a warehouse connector.
Options
create
| Option | Type | Description |
|---|---|---|
--from-dotenv, -f | str | Read KEY=value pairs from a dotenv file. |
--force | flag | Overwrite the bundle if it already exists. |
--json, -j | flag | Machine-readable output. |
list and delete also accept --json, -j.

