Penv Cloud
Start free
Docs
Reference

Woodpecker CI secrets

Repository secrets on your Woodpecker server. We expose new ones to push, tag, deployment and manual pipelines, never to pull requests, and Woodpecker never returns a value.

Repository secrets on your Woodpecker server. We expose new ones to push, tag, deployment and manual pipelines, never to pull requests, and Woodpecker never returns a value.

Connection

WhatThis provider
VendorWoodpecker CI
Keywoodpecker-secrets
Availabilityavailable. You can connect it today.
Credential we holdwoodpecker-token
Values read backno
Activationimmediate

Directions

DirectionWhat it does
exportWe write names and values from your environment into the store.

Woodpecker CI returns no value once it holds one, so we can write here and cannot read back.

Activation

immediate. The running app sees a new value at once.

Conflict policies

DirectionPolicies you can pick
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
tokenPersonal access tokensecret; we mask it here and seal ityesCopy it from User Settings, CLI & API in Woodpecker. It acts as you, so you need push access to the repository.

Connection fields

You set these when you connect. Every mapping on the connection shares them.

FieldLabelKindRequiredAdvancedWhat it is
hostServer URLtextyesnoThe address you open Woodpecker at. Must be reachable from the internet.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
repositoryIdRepository IDtextyesnoThe number after /repos/ when you open the repository in Woodpecker.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
pushevery directionyesWoodpecker refuses every secret call on the repository, so we can neither list nor write.