Skip to content
Discussion options

You must be logged in to vote

the .secrets file approach is fine, just make sure it's gitignored before you create it:

echo ".secrets" >> .gitignore

then:

# .secrets
AWS_KEY=xxx
DB_PASS=yyy
STRIPE_SECRET=zzz
act push --secret-file .secrets

for the 1password approach, write to a tmpfile instead of inline expansion — avoids the quoting nightmare with special characters:

op item get "CI Secrets" --format json \
  | jq -r '.fields[] | "\(.label)=\(.value)"' > /tmp/.act-secrets
act push --secret-file /tmp/.act-secrets
rm /tmp/.act-secrets

the tmpfile path is cleaner than chaining -s flags and keeps nothing in shell history.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by centranoisacs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants