Secrets Resolution
Runix resolves secret values from external sources at process start time.
Implementation
Located at internal/secrets/resolver.go.
Resolution Types
Environment Variable
secrets:
db_password:
type: env
value: DB_PASSWORD
Reads os.Getenv("DB_PASSWORD"). Returns error if the variable is not set or empty.
File
secrets:
api_key:
type: file
value: /run/secrets/api_key
Reads the file contents. Leading/trailing whitespace is trimmed via strings.TrimSpace().
Vault
secrets:
db_password:
type: vault
value: secret/myapp#password
Reads a secret from Vault using VAULT_ADDR and VAULT_TOKEN.
The value field uses path#key syntax. Runix attempts KV v2 lookup first and falls back to KV v1.
Masking
The MaskValue() function provides safe display of secret values:
secrets.MaskValue("my-secret-key") // "my****ey"
secrets.MaskValue("abc") // "****"
| Input Length | Output |
|---|---|
| ≤ 4 characters | **** |
| > 4 characters | First 2 + **** + Last 2 |
Resolution Flow
Security
- Secret values are never written to log output
- Secret values are not included in event payloads
- The
IsSecretEnv()helper identifies which env vars correspond to secrets for masking in status output
What's Next
- Secrets Configuration — Config file reference
- Configuration Reference — Full schema