feat: add coder secret import for bulk secret files (#27534)

Adds `coder secret import <file>` to bulk-import dotenv, JSON, or YAML
secrets through the existing batch API. The command infers the format
from the extension or accepts `--input-format`, supports non-interactive
stdin, validates files locally before upload, and warns when imported
keys cannot be injected as environment variables.

Reviewed and updated by Coder Agents on behalf of @dylanhuff-at-coder.
This commit is contained in:
dylanhuff-at-coder
2026-07-28 14:37:29 -07:00
committed by GitHub
parent 1a6a8be96c
commit 0b2a6cac78
9 changed files with 533 additions and 0 deletions
+5
View File
@@ -17,6 +17,10 @@ USAGE:
$ echo -n "$NEW_SECRET_VALUE" | coder secret update api-key --description
"Rotated API key" --env API_KEY --file "~/.api-key"
- Import secrets from a file:
$ coder secret import ./secrets.env
- List your secrets:
$ coder secret list
@@ -34,6 +38,7 @@ SUBCOMMANDS:
delete Delete a secret
disable Disable a secret without removing it
enable Enable a secret so it is injected into workspaces
import Import secrets from a file
list List secrets, or show one by name
update Update a secret
+19
View File
@@ -0,0 +1,19 @@
coder v0.0.0-devel
USAGE:
coder secret import [flags] <file>
Import secrets from a file
Every key in the file becomes a secret. Keys allowed as environment variable
names are injected into workspaces under the same name. The import is all or
nothing, and existing secrets are never overwritten. Pass - to read the file
from non-interactive stdin (pipe or redirect).
OPTIONS:
--input-format env|json|yaml
Format of the secrets file. Inferred from the file extension when
unset, and required when reading from stdin.
———
Run `coder --help` for a list of global options.