feat: add coder secret import for bulk secret files (#27534)

Adds `coder secret import <file>` to bulk-import dotenv, JSON, or YAML
secrets through the existing batch API. The command infers the format
from the extension or accepts `--input-format`, supports non-interactive
stdin, validates files locally before upload, and warns when imported
keys cannot be injected as environment variables.

Reviewed and updated by Coder Agents on behalf of @dylanhuff-at-coder.
This commit is contained in:
dylanhuff-at-coder
2026-07-28 14:37:29 -07:00
committed by GitHub
parent 1a6a8be96c
commit 0b2a6cac78
9 changed files with 533 additions and 0 deletions
+17
View File
@@ -217,6 +217,23 @@ want to store a trailing newline:
echo -n "$API_KEY" | coder secret create api-key --env API_KEY
```
### Import multiple secrets from a file
Use `coder secret import <file>` to create a secret for every key in a dotenv,
JSON, or YAML file. The format is inferred from the file extension. Pass `-`
to read from non-interactive stdin, which requires `--input-format`:
```sh
coder secret import ./secrets.env
coder secret import - --input-format yaml < ./secrets.yaml
```
The import is all or nothing and never overwrites existing secrets. Keys that
are valid environment variable names are injected under the same name; other
keys are imported without an environment variable target. For details, see
[`coder secret import`](../reference/cli/secret_import.md).
### Create a disabled secret
An enabled secret must set `--env`, `--file`, or both. To store a secret