Skip to main content
Boat injects two types of secret when a sandbox starts. Use secrets for app credentials, API keys, .env files and deployment tokens. Do not put secrets in these places:
  • Prompts.
  • URLs.
  • CLI arguments that can go into logs.
  • Docker build args.
  • Committed files.

Set secrets

The /secrets endpoint replaces all secrets. It does not merge. Send every variable and secret file that you want to keep. Boat drops the ones that you leave out. The boat env set-var and set-file commands change one item at a time, so they do not have this risk.

Secret file paths

Paths are relative to /home/user. There is no repository picker. To put a file inside a clone, start the path with the repository folder name. This path:
writes to:
Boat skips absolute paths and paths that go outside /home/user.

Variables for one sandbox

The variables of an environment apply to every sandbox that uses it. To give one sandbox its own values, pass env when you create it. Boat merges the per-sandbox values over the environment’s values. If the two have the same key, the per-sandbox value wins.
A fork gets the per-sandbox variables of its source sandbox. If the fork passes its own env, it does not get them.