Variables and secrets
← Docs · Deploy

Variables and secrets

Set variables, reference other services and share config across apps.

  • Set a variable under Variables on the app or on the canvas. Values are encrypted and applied on the next deploy.
  • Provisioned services inject their own: DATABASE_URL and DATABASE_HOST/PORT/USER/PASSWORD/NAME, REDIS_URL, CLICKHOUSE_DATABASE_URL, storage keys, and RAILYARD_HOSTNAME, RAILYARD_URL, RAILYARD_PRIVATE_URL.
  • Reference another service with ${{api.RAILYARD_PRIVATE_URL}} — resolved per environment. RAILYARD_PRIVATE_URL is http://<name>.railyard.internal:<port>; it works between apps on the same server always, and between apps on different servers of the team once the private network is on.
  • Shared config (Team → Shared config) is available as ${config.KEY} in any app.
  • Documented variables the app lists (e.g. MAIN_DB_HOST, DB_USERNAME, PGHOST, BIND_ADDRESS, APP_URL) are filled from the services above automatically; secrets the app owns (SECRET_KEY_BASE, APP_KEY, JWT_SECRET…) are generated once. Third-party keys are never invented.

File secrets

Some secrets have to be a file, not a variable: a service-account JSON, a client certificate. Add them under Variables → File secrets with a name and the content (up to 64 KB). Each is stored encrypted and mounted read-only in the container at /etc/railyard/secrets/<name>, with its path also exposed as RAILYARD_SECRET_FILE_<NAME>, so GOOGLE_APPLICATION_CREDENTIALS=${RAILYARD_SECRET_FILE_GCP_KEY_JSON} just works. Removing one takes effect on the next deploy.