Skip to content

Clarify documentation for setting secret value from a file #4038

Description

@xinatcg

CLI Feedback

I try the

gh secret set AWS_ACCESS_KEY_ID < github-secret.json

and github-secret.json

[
  {
    "key_id": "AWS_DEFAULT_REGION",
    "encrypted_value": "xxx"
  },
  {
    "key_id": "AWS_ACCESS_KEY_ID",
    "encrypted_value": "xxxxx"
  }
]

but it seem like set wrong value as auth always fail. After manually change the value on website, auth successfully.

as it is secret, cannot check the value set after the cli performed. so do i use right way? (the doc did not show what the format of json file for this api https://cli.github.com/manual/gh_secret_set)

You can use this template to give us structured feedback or just wipe it and leave us a note. Thank you!

What have you loved?

eg "the nice colors"

What was confusing or gave you pause?

eg "it did something unexpected"

Are there features you'd like to see added?

eg "gh cli needs mini-games"

Anything else?

eg "have a nice day"

Activity

  1. mislav commented on Jul 26, 2021

    @mislav
    Contributor

    @xinatcg For the value of your AWS_ACCESS_KEY_ID secret you have used an entire JSON document, but that's probably not what the value should be. The value of AWS_ACCESS_KEY_ID should be your access ID (a single string) and the value of AWS_SECRET_ACCESS_KEY should be your access secret (also a single string), unencrypted.

    I do not know what github-secret.json is and what its format is, but from what I can see, you shouldn't use that JSON document in combination with gh secret set. Use raw values instead.

  2. xinatcg commented on Jul 29, 2021

    @xinatcg
    Author

    @xinatcg For the value of your AWS_ACCESS_KEY_ID secret you have used an entire JSON document, but that's probably not what the value should be. The value of AWS_ACCESS_KEY_ID should be your access ID (a single string) and the value of AWS_SECRET_ACCESS_KEY should be your access secret (also a single string), unencrypted.

    I do not know what github-secret.json is and what its format is, but from what I can see, you shouldn't use that JSON document in combination with gh secret set. Use raw values instead.

    the document said, but without json format description

    Use file as secret value
    $ gh secret set MYSECRET < file.json
    

    image

  3. xinatcg commented on Jul 29, 2021

    @xinatcg
    Author

    ou shouldn't use that JSON document in combination with gh secret set. Use raw values instead.

    So there is something wrong with document? but i think use json as input is more convenient

  4. mislav commented on Aug 2, 2021

    @mislav
    Contributor

    Hi, that example just shows how to populate a secret with an entire contents of a file, and uses a json file as an example, but that example might be misleading. A secret value that has JSON as a contents is likely not really useful in a real world scenario.

    A better example might be this:

    # file `token.txt` contains just the value of a secret token
    $ gh secret set MYSECRET < token.txt
    

    I'm going to reopen this issue as a task to improve this detail in the documentation. Ref. #2529

  5. reopened this on Aug 2, 2021
  6. changed the title [-]I try to use the secret set command but seem like the value set is wrong[/-] [+]Clarify documentation for setting secret value from a file[/+] on Aug 2, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions