rebase secret

Store workspace secrets to reference from secrets= on functions, models, and apps.

Synopsis

rebase secret create <name> KEY=value [KEY=value ...]
rebase secret create <name> KEY=-
rebase secret create <name> --from-dotenv .env
rebase secret list [--json]
rebase secret delete <name> [--json]

Subcommands

SubcommandArgumentsDescription
create<name> [KEY=value]...Create a secret bundle: a named set of environment variables.
delete<name>Delete a secret bundle and all of its keys.
listnoneList secret bundles and their keys, never their values.

Behavior

Values are written to Secret Manager and never stored or shown by Rebase. Attach a bundle in code with secrets=[rebase.Secret.from_name("<name>")]; every key becomes an environment variable in the container.

KEY=- reads that one value from stdin, so it stays out of your shell history. Only one key per command may read from stdin. With --from-dotenv, pairs given on the command line override the same keys from the file. create refuses a name that already exists unless you pass --force.

printf '%s' "$SNOWFLAKE_PASSWORD" | rebase secret create snowflake SNOWFLAKE_USER=me SNOWFLAKE_PASSWORD=-

See Credentials for how a bundle is used from a warehouse connector.

Options

create

OptionTypeDescription
--from-dotenv, -fstrRead KEY=value pairs from a dotenv file.
--forceflagOverwrite the bundle if it already exists.
--json, -jflagMachine-readable output.

list and delete also accept --json, -j.

On this page