Secrets & Environment
Secrets & Environment
fj-act has two separate flag families for feeding data into a
workflow run, and they behave differently on purpose. Mixing them up is
the most common source of “why isn’t my value showing up” confusion.
--secret/--var vs --env/--input
Populates ${{ secrets.KEY }} / ${{ vars.KEY }}. Key is upper-cased. A bare KEY (no =value) first checks your shell’s own environment, then prompts interactively with hidden input if still unset.
Populates env vars in the job / ${{ inputs.KEY }}. Plain KEY=VALUE splitting. A bare KEY with no = just becomes an empty string — no shell fallback, no prompt.
# prompts for MY_SECRET if it's not already in your shell env
fj-act -s MY_SECRET
# explicit value, upper-cased to MY_SECRET either way
fj-act -s my_secret=hunter2
# plain KEY=VALUE, no case conversion, no prompting
fj-act --env FOO=bar--insecure-secrets turns off masking secret values in log output —
useful for debugging a run locally, never for anything you’d share.
File-backed equivalents
Each flag family has a matching --*-file flag, so you don’t have to pass
everything on the command line:
| Flag | Default file | Format |
|---|---|---|
--secret-file | .secrets | .yml/.yaml → parsed as a YAML map; anything else → dotenv syntax |
--var-file | .vars | same |
--env-file | .env | same |
--input-file | .input | same |
Dotenv syntax (via godotenv) supports
quoted, multi-line values:
# .secrets
MY_SECRET=top-secret
MULTILINE_SECRET="foo\nbar\nbaz"
JSON_SECRET={"foo": "bar"}# .env
HELLO=WORLD
MULTILINE_ENV="foo\nbar\nbaz"For --secret-file/--var-file specifically, keys are upper-cased on
load to match the CLI-flag convention (my_secret= in the file still
lands as ${{ secrets.MY_SECRET }}).
A command-line value always wins over the same key in a file.
readEnvsEx only fills in keys that aren’t already set — so
-s MY_SECRET=cli-value beats whatever .secrets says for
MY_SECRET, letting you override one value locally without editing the
file.Token resolution
If you don’t pass a GITHUB_TOKEN secret explicitly, fj-act tries, in
order:
GITHUB_TOKENfrom-s/.secrets, if present.FORGEJO_TOKENfrom-s/.secrets, copied intoGITHUB_TOKEN— this is the one most Codeberg/Forgejo users actually want to set.- The GitHub CLI (
gh auth token), ifghis onPATH.
There’s currently no Forgejo/Gitea CLI (
tea) fallback — if you’re not
using GitHub at all, set FORGEJO_TOKEN explicitly (-s FORGEJO_TOKEN or
in .secrets) rather than relying on step 3.