Secrets and keys
A secret goes in once and never comes back out. ix delivers it only to the machines you name, as an environment variable or a file. A key is how your code reaches ix, with its own spending ceiling and permissions.
Store a secret
- Store the secret once with
ix secret set. The name uses lower snake case. - Name the machines that can see it, and the variable it appears as, when you boot them.
- Create a key for each service, with a ceiling in dollars.
ix secret set github_token # reads the value from a hidden prompt
ix new --name ci --secret-env github_token=GH_TOKEN
ix keys create customer-42 --limit 100To give a machine a secret as a file, use --secret-file KEY=PATH or secretFiles. If you store a secret again under the same name, ix pushes the new value to the machines that have it. An environment variable changes at the next start of the machine.
Run ix keys ls to list your keys and what each has spent. Run ix keys update <id> --disable to pause a key, and ix keys revoke <id> to end it for good.