Secrets & variables

Manage secrets and variables across services, environments, and projects, secure storage with per-environment overrides.

Services need configuration that changes per environment and must not be hardcoded: feature flags, external API keys and secrets, and credentials like database URLs and passwords. Facets models all of it as variables and secrets, injected at runtime with the right value for each environment.

You manage them at two levels:

  • Project-level secrets and variables: define a variable or secret once as the single source of truth, auto-inject it across resources, and override its value per environment.
  • Resource variables: variables scoped to a single resource, with blueprint defaults you can override per environment.

Secret values are stored securely in the environment's secrets backend, never in Git. Project-level defaults can be overridden per environment; see Environment-level management to compare and bulk-edit across environments.

To wire one resource's output (a database URL, username, or password) directly into another, use Linking resources.

Using variables in code

Read an injected variable the usual way.

// Node.js
const myEnvVariable = process.env.MY_ENV_VARIABLE;
# Python
import os
my_env_variable = os.getenv('MY_ENV_VARIABLE')