Skip to main content

deployer_secret_environment

Function deployer_secret_environment 

Source
pub fn deployer_secret_environment(
    inputs: &[StackInputDefinition],
    values: &HashMap<String, Value>,
    platform: Platform,
    reports: &[DeployerSecretReport],
) -> Vec<(DeployerSecretEnv, Option<Vec<String>>)>
Expand description

The environment variables workloads read from vault-native deployer secrets, each with the resources its mapping targets (None = all).

A slot is read from the vault once Alien has a report for it, unless the deployment still stores a value from before slots were vault-native: that value keeps today’s path until the control plane drops it. The workload’s profile gains the vault read grant at the same point, so a workload never reads a slot it may not read.