stackapRequest access

Product

Environment variables and secrets

Stackap stores each environment variable encrypted and bound to its project and name, never shows the value back, and hands it to your app through a private file at start.

What it does

You set a variable with stackap env set <slug> KEY --stdin, and the value comes from standard input, so it never appears in a command line, a shell history or an agent's transcript. Setting the same key again replaces it. Removing one is env rm.

Each value is encrypted with AES-256-GCM under the platform's master key, and the project and the variable name are bound into the encryption, so a stored value cannot be copied from one project or key to another and still decrypt. Listing variables returns the names and a mask, never the values.

A few variables are managed by Stackap itself, such as the one carrying the database connection string. Those are flagged as system variables, and an attempt to change or delete one is refused with a clear message.

How it works

When a container starts, the values are written to a private file readable only by the process that launches it and passed to the container from there. They are not placed on a command line, where any process listing could read them. The audit log records that a variable was set or removed, with the key and never the value.

Because values are read when a container starts, a changed value reaches the app on its next start or deploy. During a build the rule is different and deliberate: names beginning with NEXT_PUBLIC_ are passed through, because they are public by design, and every other value is replaced by a placeholder, so no secret is baked into an image layer.

The master key

The encryption is only as recoverable as the master key. If it is lost, every stored variable and every backup is unreadable. Keep a copy outside the server.

In practice

$ stackap env ls my-app
$ stackap env set my-app API_KEY --stdin
$ stackap env rm my-app OLD_KEY

Early-access scope

Questions

Can a teammate see my secrets?
Not through Stackap: values are masked in every listing. A person with root access to the server and the master key could decrypt them, which is true of any self-hosted system.
Can I import a .env file?
There is no import command. Set each variable with env set.

Stackap is in early access. Tell us what you run and we will reply with a straight answer about whether it fits.

Ask for an invitation

Last updated .