Docs
Reference

Fastly Secret Store

Write-only secrets a Compute service reads at the edge, written and pruned per secret.

Write-only secrets a Compute service reads at the edge, written and pruned per secret.

The connection

WhatThis provider
VendorFastly
Keyfastly-secret-store
Availabilityavailable. You can connect it today.
Credential penv holdsfastly-key
Values read backno
Activationimmediate

What it moves

DirectionWhat it does
exportWrites names and values from penv into the store.

Fastly returns no value once it holds one, so penv can write here and cannot read back.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
apiTokenAPI tokensecret, masked here and sealedyesNeeds global scope, because a secret store belongs to the account rather than a service.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
storeIdStoretextyesnoThe secret store's ID. Pruning deletes every secret in it, including ones this sync did not write.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
secret-store:readevery directionyesPreview cannot list the secrets in the store.
secret-store:writeexportyesExport cannot write a secret.