Docs
Reference

Windmill

Workspace variables and secrets, read one at a time.

Workspace variables and secrets, read one at a time.

The connection

WhatThis provider
VendorWindmill
Keywindmill-variables
Availabilityavailable. You can connect it today.
Credential penv holdswindmill-token
Values read backyes
Activationimmediate

What it moves

DirectionWhat it does
importReads names and values out of the store into penv.
exportWrites names and values from penv into the store.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
tokenTokensecret, masked here and sealedyesMinted from your Windmill account settings, and scoped to the workspace below.

What the connection asks for

Fixed when you connect, and shared by every mapping on it.

FieldLabelKindRequiredAdvancedWhat it is
workspaceWorkspacetextyesnoThe workspace ID from the Windmill URL. Its display name is a different value.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
folderFoldertextyesnopenv writes under f/{folder}/. It never writes into a person's u/ namespace, and pruning deletes every variable in the folder, including ones this sync did not write.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
workspace:readevery directionyesPreview cannot list the workspace's variables.
workspace:writeexportyesExport cannot create, change or remove a variable.