Variables and secrets
Set variables, reference other services and share config across apps.
- Set a variable under Variables on the app or on the canvas. Values are encrypted and applied on the next deploy.
- Provisioned services inject their own:
DATABASE_URLandDATABASE_HOST/PORT/USER/PASSWORD/NAME,REDIS_URL,CLICKHOUSE_DATABASE_URL, storage keys, andRAILYARD_HOSTNAME,RAILYARD_URL,RAILYARD_PRIVATE_URL. - Reference another service with
${{api.RAILYARD_PRIVATE_URL}}— resolved per environment.RAILYARD_PRIVATE_URLishttp://<name>.railyard.internal:<port>; it works between apps on the same server always, and between apps on different servers of the team once the private network is on. - Shared config (Team → Shared config) is available as
${config.KEY}in any app. - Documented variables the app lists (e.g.
MAIN_DB_HOST,DB_USERNAME,PGHOST,BIND_ADDRESS,APP_URL) are filled from the services above automatically; secrets the app owns (SECRET_KEY_BASE,APP_KEY,JWT_SECRET…) are generated once. Third-party keys are never invented.
File secrets
Some secrets have to be a file, not a variable: a service-account JSON, a client certificate. Add them under Variables → File secrets with a name and the content (up to 64 KB). Each is stored encrypted and mounted read-only in the container at /etc/railyard/secrets/<name>, with its path also exposed as RAILYARD_SECRET_FILE_<NAME>, so GOOGLE_APPLICATION_CREDENTIALS=${RAILYARD_SECRET_FILE_GCP_KEY_JSON} just works. Removing one takes effect on the next deploy.