Skip to content

feat: Support secret and build-time environment variables - #87

Merged
Pijukatel merged 10 commits into
masterfrom
claude/vigilant-ride-8jpzmu
Sep 30, 2026
Merged

Pijukatel merged 10 commits into
masterfrom
claude/vigilant-ride-8jpzmu

Conversation

@Pijukatel

@Pijukatel Pijukatel commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator
  • Secret env vars (isSecret) are stored encrypted with a per-Actor key pair (simplified vs. the platform, listed in its differences), reach the run, are never returned by the API (versions show a valueHash), and are masked in run logs along with APIFY_TOKEN, as on the platform.
  • Secret input fields are stored encrypted in the run's INPUT, and every run gets its Actor's private key as APIFY_INPUT_SECRETS_PRIVATE_KEY_FILE/_PASSPHRASE, so the SDKs' getInput() decrypts them.
  • With applyEnvVarsToBuild on, a version's env vars (secrets included) are passed to the image build as Docker build arguments; the build log names them, never their values.
  • New v2/actors/:actorId/versions/:versionNumber/env-vars endpoints; env vars are validated with the platform's rules and error types.
  • New samples/actor_env_vars: logs one env var read during the build, and one plain env var, one secret and one secret input field read during the run.

Secret env vars are passed to runs but never returned by the API (versions carry a
short valueHash instead). With applyEnvVarsToBuild on, a version's env vars are
passed to the image build as Docker build arguments. Adds the per-version env-vars
endpoints.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
@Pijukatel
Pijukatel force-pushed the claude/vigilant-ride-8jpzmu branch from fd6bc62 to e2a27c0 Compare September 30, 2026 06:40
Each Actor gets its own RSA key pair with its first secret or run. Secret
env vars are stored encrypted with the platform's scheme and decrypted only
for that Actor's builds and runs, and every run gets the private key as
APIFY_INPUT_SECRETS_PRIVATE_KEY_FILE/_PASSPHRASE, which the SDKs use to
decrypt secret input fields.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
After validation and defaults, isSecret input fields are stored in the
run's INPUT encrypted with the Actor's public key, as on the platform, so
the SDKs' getInput() decrypts them with the run's private key vars.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
@Pijukatel
Pijukatel marked this pull request as ready for review September 30, 2026 07:10
Version POST/PUT responses showed the first characters of a secret's plain
value as its valueHash; they now answer with the stored version, whose
valueHash is the start of the encrypted value. Every Actor gets its key pair
on creation, generated asynchronously; a version holds at most 100 env vars,
as on the platform; a run fails instead of storing secret input unencrypted.
Test Docker stubs share one capturing driver.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
The sample now uses the Apify SDK, preinstalled in its base image, so a
secret input field is decrypted by Actor.getInput(). The build failure and
README name the platform's Code > Environment variables switch.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
…tform

A run's log shows ********* in place of every exact occurrence of its secret
env vars' values and its APIFY_TOKEN, including one split across output
chunks. Secret input fields and values printed in another form are left as
they are, matching what the platform does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
The sample now prints API_KEY and the secret input field as they are, so
its run log shows which one is masked and which is not.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
…erences

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1zam1ZogiR2VjVyLXie9L
@Pijukatel
Pijukatel merged commit 015fef2 into master Sep 30, 2026
30 checks passed
@Pijukatel
Pijukatel deleted the claude/vigilant-ride-8jpzmu branch September 30, 2026 09:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants