Penv Cloud
Start free
Docs
Reference

Upsun

Sync an environment with an Upsun environment's env: variables.

Sync an environment with an Upsun environment's env: variables.

Connection

WhatThis provider
VendorUpsun
Keyupsun-variables
Availabilityavailable. You can connect it today.
Credential we holdupsun-token
Values read backyes
Activationrestart-on-write

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

restart-on-write. When we write a value, the workload restarts.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
apiTokenAPI tokensecret; we mask it here and seal ityesCreate it in the Console under My profile, API tokens. We trade it for a 15 minute access token on each run and never store that one.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
projectIdProject IDtextyesnoThe ID in the project's Console URL, or the ID column of upsun projects.
environmentIdEnvironment IDtextyesnoThe ID column of upsun environments, usually the branch name. We sync only its own env: variables. Each variable we write or delete redeploys it. We create variables that child environments do not inherit. Export stops, before any write, on a key the environment inherits from its parent. Import stops on a disabled variable or one hidden at runtime, and export will not update one, because the app never sees it.
sensitiveCreate as sensitiveyes or nonoyesOne way: Upsun hides a sensitive value from the API, so we cannot import it back. We only set this on variables we create. Starts at false.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
Viewer role on the environment typeevery directionyesPreview cannot list the environment's variables.
Admin role on the environment typeexportyesExport cannot add, change or delete a variable.