Environment variables

Manage environment variables in Facets: migrate from .env files or parameter stores, set project-wide and resource-specific values, and handle secrets securely.

Managing environment variables in Facets.cloud provides a structured way to handle application configurations across different environments. Whether you're migrating from a .env file or a cloud provider's parameter store, here's how to set up your environment variables effectively.

To know more about what are secrets and variables in Facets, Secrets & Variables

Setting Up Your Variables

Migrating Existing Variables

  • Review your current .env files or configuration management
  • Identify variables that should be project-wide vs resource-specific
  • Determine which values need environment-specific overrides

Configuring in Facets

Using prompt

Add a project-wide variable API_ENDPOINT set to https://api.example.com in myproject, and auto-inject it.

or

Using command

# Create a variable, --global auto-injects it into every resource
raptor create variable API_ENDPOINT --value https://api.example.com --global -p myproject

# Change it later
raptor set variable API_ENDPOINT --value https://api.v2.example.com -p myproject

# Different value per environment
raptor set variable API_URL -p myproject \
    --env-values prod=https://api.prod.com,staging=https://api.staging.com

# See what a project has. Secrets come back masked
raptor get variables -p myproject

A secret has no project-wide default. Its value is set per environment through --env-values, one environment at a time, even when the value is the same everywhere.

New to the CLI? Install it first.

  • Add project-wide secrets and variables from "Secrets and Variables" tab in your project. Configure auto-injection for commonly used variables to be used across all resources.
  • Navigate to your Service Configuration Tab and add resource-specific variables in "Environment Variables" section or in JSON configuration. Non-auto-injected variables if needed can be aliased in the resource as well.

Finding what is unused

Before deleting a variable or a secret, check what still references it. With no name, the command lists everything in the project including the entries nothing uses, which are the safe ones to remove.

raptor get variable-usages DB_PASSWORD -p myproject
raptor get variable-usages -p myproject

Managing Sensitive Data

  • Use Secrets for sensitive values
  • Only define secret keys in the blueprint
  • Set actual values at environment level
  • Utilise secret manager integration for enhanced security