Penv Cloud
Start free
Docs
Reference

Scalr workspace variables

Sync an environment with one Scalr workspace's shell variables.

Sync an environment with one Scalr workspace's shell variables.

Connection

WhatThis provider
VendorScalr
Keyscalr-variables
Availabilityavailable. You can connect it today.
Credential we holdscalr-token
Values read backyes
Activationon-next-deploy

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

on-next-deploy. A new value waits there and arrives with your next deploy.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
tokenAPI tokensecret; we mask it here and seal ityesA service account token. At the account scope, open Security, then IAM, then Service accounts, pick or create a service account, and create a token for it. Give it an access policy on the workspace with a role that has the variable:* permission.

Connection fields

You set these when you connect. Every mapping on the connection shares them.

FieldLabelKindRequiredAdvancedWhat it is
accountAccounttextyesnoThe part of your Scalr address before .scalr.io.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
workspaceIdWorkspace IDtextyesnoFrom the workspace URL. We sync its shell variables and never touch the ones it inherits from the environment or account. Pruning deletes every shell variable of this workspace that this environment lacks, including ones this sync did not write.
sensitiveMark written variables sensitiveyes or noyesyesScalr never shows a sensitive value again, including to import, and a sensitive variable cannot be made plain. We never turn it off on a variable that has it. Starts at true.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
Role with the variable:* permissionevery directionyesWe cannot list the workspace's variables, or add, change or remove one on export.