Skip to main content

Secrets Resolution

Runix resolves secret values from external sources at process start time.

Implementation​

Located at internal/secrets/resolver.go.

Resolution Types​

Environment Variable​

secrets:
db_password:
type: env
value: DB_PASSWORD

Reads os.Getenv("DB_PASSWORD"). Returns error if the variable is not set or empty.

File​

secrets:
api_key:
type: file
value: /run/secrets/api_key

Reads the file contents. Leading/trailing whitespace is trimmed via strings.TrimSpace().

Vault​

secrets:
db_password:
type: vault
value: secret/myapp#password

Reads a secret from Vault using VAULT_ADDR and VAULT_TOKEN.

The value field uses path#key syntax. Runix attempts KV v2 lookup first and falls back to KV v1.

Masking​

The MaskValue() function provides safe display of secret values:

secrets.MaskValue("my-secret-key") // "my****ey"
secrets.MaskValue("abc") // "****"
Input LengthOutput
≤ 4 characters****
> 4 charactersFirst 2 + **** + Last 2

Resolution Flow​

Security​

  • Secret values are never written to log output
  • Secret values are not included in event payloads
  • The IsSecretEnv() helper identifies which env vars correspond to secrets for masking in status output

What's Next​