Where to store environment variables in App Engine for CI/CD Pipeline?

Viewed 1674

I am deploying my first application on the cloud and I'm trying to setup my env vars.

From what I understand, they are set in the app.yaml file. But if that file is pushed to the repo, it would then contain the secret API keys which is bad..

I could treat the app.yaml the same way I treat the .env but the problem is, how can I set env vars for prod in a CI/CD pipeline?

I am using Cloud Build to run my build pipeline. I am coming from Bitbucket & Heroku and there doesn't seem to be a way to "set" the env vars for the build environment like on those two platforms.

So then, how can I make my .env variables available in my app without taking risks of pushing it on my repo?

Thank you for your help

2 Answers

For those looking, here is how I solved this problem.

I followed the steps outlined in this blog post.

Basically we set variables in the .yaml file, which we then compile into an .env file during the build process. We can set what the value of those variables is via Cloud Build configuration so we can restrict access to them and have them hidden.

I have a 'deploy' script that clones my app.yaml, downloads api-keys from google-secret-manager, and injects them as environment variables into the env_variables section of app.yaml and then runs the deploy command using that new app.yaml instead of the original.

For me this script is a local thing, but i imagine you could do something similar in google-cloud-build

Related