Docs
Reference

Buildkite cluster secrets

Export secrets into a Buildkite cluster.

Export secrets into a Buildkite cluster.

The connection

WhatThis provider
VendorBuildkite
Keybuildkite-cluster-secrets
Availabilityavailable. You can connect it today.
Credential penv holdsbuildkite-token
Values read backno
Activationimmediate

What it moves

DirectionWhat it does
exportWrites names and values from penv into the store.

Buildkite returns no value once it holds one, so penv can write here and cannot read back.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
tokenAPI access tokensecret, masked here and sealedyesAn API access token with read_secret_details and write_secrets.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
organizationSlugOrganizationtextyesnoThe slug in your Buildkite URL.
clusterIdClustertextyesnoSecrets belong to one cluster. Its ID is in the cluster's URL.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
read_secret_detailsevery directionyesPreview cannot list the cluster's secrets.
write_secretsexportyesExport cannot write anything.