Repository navigation
feat: Support secret and build-time environment variables - #87
Merged
Merged
Conversation
Secret env vars are passed to runs but never returned by the API (versions carry a short valueHash instead). With applyEnvVarsToBuild on, a version's env vars are passed to the image build as Docker build arguments. Adds the per-version env-vars endpoints. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
Pijukatel
force-pushed
the
claude/vigilant-ride-8jpzmu
branch
from
September 30, 2026 06:40
fd6bc62 to
e2a27c0
Compare
Each Actor gets its own RSA key pair with its first secret or run. Secret env vars are stored encrypted with the platform's scheme and decrypted only for that Actor's builds and runs, and every run gets the private key as APIFY_INPUT_SECRETS_PRIVATE_KEY_FILE/_PASSPHRASE, which the SDKs use to decrypt secret input fields. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
After validation and defaults, isSecret input fields are stored in the run's INPUT encrypted with the Actor's public key, as on the platform, so the SDKs' getInput() decrypts them with the run's private key vars. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
Pijukatel
marked this pull request as ready for review
September 30, 2026 07:10
Version POST/PUT responses showed the first characters of a secret's plain value as its valueHash; they now answer with the stored version, whose valueHash is the start of the encrypted value. Every Actor gets its key pair on creation, generated asynchronously; a version holds at most 100 env vars, as on the platform; a run fails instead of storing secret input unencrypted. Test Docker stubs share one capturing driver. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
The sample now uses the Apify SDK, preinstalled in its base image, so a secret input field is decrypted by Actor.getInput(). The build failure and README name the platform's Code > Environment variables switch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
…mples Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
…tform A run's log shows ********* in place of every exact occurrence of its secret env vars' values and its APIFY_TOKEN, including one split across output chunks. Secret input fields and values printed in another form are left as they are, matching what the platform does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
The sample now prints API_KEY and the secret input field as they are, so its run log shows which one is masked and which is not. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
…erences Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
isSecret) are stored encrypted with a per-Actor key pair (simplified vs. the platform, listed in its differences), reach the run, are never returned by the API (versions show avalueHash), and are masked in run logs along withAPIFY_TOKEN, as on the platform.INPUT, and every run gets its Actor's private key asAPIFY_INPUT_SECRETS_PRIVATE_KEY_FILE/_PASSPHRASE, so the SDKs'getInput()decrypts them.applyEnvVarsToBuildon, a version's env vars (secrets included) are passed to the image build as Docker build arguments; the build log names them, never their values.v2/actors/:actorId/versions/:versionNumber/env-varsendpoints; env vars are validated with the platform's rules and error types.samples/actor_env_vars: logs one env var read during the build, and one plain env var, one secret and one secret input field read during the run.