Reference
Upsun
Sync an environment with an Upsun environment's env: variables.
Sync an environment with an Upsun environment's env: variables.
Connection
| What | This provider |
|---|---|
| Vendor | Upsun |
| Key | upsun-variables |
| Availability | available. You can connect it today. |
| Credential we hold | upsun-token |
| Values read back | yes |
| Activation | restart-on-write |
Directions
| Direction | What it does |
|---|---|
import | We read names and values out of the store into your environment. |
export | We write names and values from your environment into the store. |
Activation
restart-on-write. When we write a value, the workload restarts.
Conflict policies
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
Connect
Paste a credential from the vendor. We seal it and never show it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
apiToken | API token | secret; we mask it here and seal it | yes | Create it in the Console under My profile, API tokens. We trade it for a 15 minute access token on each run and never store that one. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
projectId | Project ID | text | yes | no | The ID in the project's Console URL, or the ID column of upsun projects. |
environmentId | Environment ID | text | yes | no | The ID column of upsun environments, usually the branch name. We sync only its own env: variables. Each variable we write or delete redeploys it. We create variables that child environments do not inherit. Export stops, before any write, on a key the environment inherits from its parent. Import stops on a disabled variable or one hidden at runtime, and export will not update one, because the app never sees it. |
sensitive | Create as sensitive | yes or no | no | yes | One way: Upsun hides a sensitive value from the API, so we cannot import it back. We only set this on variables we create. Starts at false. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
Viewer role on the environment type | every direction | yes | Preview cannot list the environment's variables. |
Admin role on the environment type | export | yes | Export cannot add, change or delete a variable. |