Secrets

Storing private repository credentials and webhook signing keys, and using them in your deploys.

Secrets are for sensitive values your deploys need but that shouldn't sit in plain text alongside your other configuration — most commonly a private repository access token or a webhook signing key. Unlike environment variables, a secret isn't attached directly to an App; instead, your App's source (or webhook) configuration references a secret by picking it from a list.

Creating a secret

From your Organization's Secrets page, create a new secret with:

  • A name you'll recognize later (e.g. github-deploy-token).
  • A kind: token, ssh_key, docker_config, tls_cert, password, or webhook_secret — pick whichever matches what you're storing.
  • The value itself.

Once created, a secret's value is never shown again in the dashboard — only referenced by name when you configure something that needs it. If you need to change the value later, rotate it from the Secrets page — this replaces the stored value in place while keeping the same secret, so anything already referencing it (an App's source, a webhook) picks up the new value without you needing to update those references.

Private repositories

To deploy from a private Git repository:

  1. Create a secret of kind token (a personal access token from GitHub/GitLab/Bitbucket with read access to the repo) or ssh_key.
  2. When configuring your App's source (see Deploying Your App), select that secret alongside your repository URL and ref.

Raklane uses the referenced credential to clone your repository at deploy time. If the token is later revoked, expires, or has its permissions changed, your next deploy will fail to fetch the repo — update the secret (or point your App's source at a fresh one) to fix it.

Webhook secrets

Auto-deploying on git push requires a secret of kind webhook_secret, shared between your App's source configuration and the webhook you set up on your Git provider. See Auto-Deploy & Deploy Modes for the full setup.

See also