Skip to content
Secrets & Environment

Secrets & Environment

fj-act has two separate flag families for feeding data into a workflow run, and they behave differently on purpose. Mixing them up is the most common source of “why isn’t my value showing up” confusion.

--secret/--var vs --env/--input

# prompts for MY_SECRET if it's not already in your shell env
fj-act -s MY_SECRET

# explicit value, upper-cased to MY_SECRET either way
fj-act -s my_secret=hunter2

# plain KEY=VALUE, no case conversion, no prompting
fj-act --env FOO=bar

--insecure-secrets turns off masking secret values in log output — useful for debugging a run locally, never for anything you’d share.

File-backed equivalents

Each flag family has a matching --*-file flag, so you don’t have to pass everything on the command line:

FlagDefault fileFormat
--secret-file.secrets.yml/.yaml → parsed as a YAML map; anything else → dotenv syntax
--var-file.varssame
--env-file.envsame
--input-file.inputsame

Dotenv syntax (via godotenv) supports quoted, multi-line values:

# .secrets
MY_SECRET=top-secret
MULTILINE_SECRET="foo\nbar\nbaz"
JSON_SECRET={"foo": "bar"}
# .env
HELLO=WORLD
MULTILINE_ENV="foo\nbar\nbaz"

For --secret-file/--var-file specifically, keys are upper-cased on load to match the CLI-flag convention (my_secret= in the file still lands as ${{ secrets.MY_SECRET }}).

A command-line value always wins over the same key in a file. readEnvsEx only fills in keys that aren’t already set — so -s MY_SECRET=cli-value beats whatever .secrets says for MY_SECRET, letting you override one value locally without editing the file.

Token resolution

If you don’t pass a GITHUB_TOKEN secret explicitly, fj-act tries, in order:

  1. GITHUB_TOKEN from -s/.secrets, if present.
  2. FORGEJO_TOKEN from -s/.secrets, copied into GITHUB_TOKEN — this is the one most Codeberg/Forgejo users actually want to set.
  3. The GitHub CLI (gh auth token), if gh is on PATH.
There’s currently no Forgejo/Gitea CLI (tea) fallback — if you’re not using GitHub at all, set FORGEJO_TOKEN explicitly (-s FORGEJO_TOKEN or in .secrets) rather than relying on step 3.