Reference
Phase
Sync an environment with one folder of a Phase app environment, in either direction.
Sync an environment with one folder of a Phase app environment, in either direction.
Connection
| What | This provider |
|---|---|
| Vendor | Phase |
| Key | phase-secrets |
| Availability | available. You can connect it today. |
| Credential we hold | phase-token |
| Values read back | yes |
| Activation | immediate |
Directions
| Direction | What it does |
|---|---|
import | We read names and values out of the store into your environment. |
export | We write names and values from your environment into the store. |
Activation
immediate. The running app sees a new value at once.
Conflict policies
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
Connect
Paste a credential from the vendor. We seal it and never show it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
token | Service account token | secret; we mask it here and seal it | yes | In the Phase console, open Access, then Service Accounts, create a token, and add the account to the app. The Service role grants everything a sync needs. |
Connection fields
You set these when you connect. Every mapping on the connection shares them.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
host | Instance URL | text | no | yes | Leave empty for Phase Cloud. For your own instance, the address you open the console at. It must be reachable from the internet. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
appId | App ID | text | yes | no | From the app's Settings page in the Phase console. |
environment | Environment | text | yes | no | The environment name as the app lists it. |
path | Folder | text | no | yes | One folder per sync. We do not walk subfolders, and pruning deletes every secret in this folder that this environment lacks. Starts at /. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
Apps:read | every direction | yes | We cannot confirm the token or see which apps have server-side encryption. |
server-side-encryption | every direction | no | Phase refuses API access to an app without server-side encryption. Turn it on in the app's Settings page. |
Secrets:read | every direction | yes | Preview cannot list the folder, and import cannot read a value. |
Secrets:create | export | yes | Export cannot add a secret. |
Secrets:update | export | yes | Export cannot change a secret that already exists. |
Secrets:delete | export | no | Prune cannot remove a secret. |