Woodpecker CI secrets
Repository secrets on your Woodpecker server. We expose new ones to push, tag, deployment and manual pipelines, never to pull requests, and Woodpecker never returns a value.
Repository secrets on your Woodpecker server. We expose new ones to push, tag, deployment and manual pipelines, never to pull requests, and Woodpecker never returns a value.
Connection
| What | This provider |
|---|---|
| Vendor | Woodpecker CI |
| Key | woodpecker-secrets |
| Availability | available. You can connect it today. |
| Credential we hold | woodpecker-token |
| Values read back | no |
| Activation | immediate |
Directions
| Direction | What it does |
|---|---|
export | We write names and values from your environment into the store. |
Woodpecker CI returns no value once it holds one, so we can write here and cannot read back.
Activation
immediate. The running app sees a new value at once.
Conflict policies
| Direction | Policies you can pick |
|---|---|
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
Connect
Paste a credential from the vendor. We seal it and never show it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
token | Personal access token | secret; we mask it here and seal it | yes | Copy it from User Settings, CLI & API in Woodpecker. It acts as you, so you need push access to the repository. |
Connection fields
You set these when you connect. Every mapping on the connection shares them.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
host | Server URL | text | yes | no | The address you open Woodpecker at. Must be reachable from the internet. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
repositoryId | Repository ID | text | yes | no | The number after /repos/ when you open the repository in Woodpecker. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
push | every direction | yes | Woodpecker refuses every secret call on the repository, so we can neither list nor write. |
Related
Gitea Actions organization secrets
Actions secrets on a Gitea organization, which every repository in it reads. We write and prune them per secret, and Gitea never returns a value.
Travis CI environment variables
Repository variables set for all branches on Travis CI. We write them private. Import reads public values in plain or single-quoted text and refuses a private one, which Travis never returns.