Manage application secrets
Application secrets let services consume sensitive values without placing those values directly in an environment-variable configuration.
Create and assign a secret
- Open an application and select Secrets.
- Select Add secret, enter a name and value, and save it.
- Open a service's Manage environment variables dialog.
- Add an environment variable, enable Reference secret, and select the secret.
The Secrets table shows every service using each secret. Service names are links to the corresponding service page. Revealing a value displays sensitive information in the browser; hide it again when it is no longer needed.
Reading secrets requires READ access. Creating, editing, assigning, or deleting them requires WRITE access and the environment's required credentials.
Delete a secret
An unused secret can be deleted directly. EasyHosting refuses an ordinary deletion while any service references the secret.
For a secret in use, the confirmation dialog lists the affected services. Selecting Remove from services and delete performs a bulk removal: EasyHosting removes every environment variable referencing the secret from those services and deletes the secret only after all references have been removed.
If a service update fails, the secret remains available. Some services may already have been updated; review the refreshed usage list and retry the operation. Unrelated environment variables and references to other secrets are preserved.
Storage and compatibility
EasyHosting stores secret identity and service usage in its database, while the sensitive value remains in Kubernetes. Secrets that existed only in Kubernetes before this model was introduced are not imported, discovered, or repaired automatically.