feat: add bulk secret import upload to Add secret dialog (PLAT-240) (#26725)

Adds a file dropzone to the create branch of the Add secret dialog
(final PR in the PLAT-240 stack, after #26723 and #26724). The browser
reads the file, derives the format from the extension
(`.env`/`.json`/`.yaml`/`.yml`), and imports via `POST /secrets/batch`;
per-entry backend errors surface in an alert and the success toast flags
secrets imported without an env name. Storybook play stories and vitests
cover the flow.

Also documents the upload flow in `docs/user-guides/user-secrets.md`.

Closes https://linear.app/codercom/issue/PLAT-240

> Reviewed and updated by Coder Agents on behalf of @dylanhuff-at-coder.
This commit is contained in:
dylanhuff-at-coder
2026-07-28 15:30:15 -07:00
committed by GitHub
parent 0b2a6cac78
commit efbf802319
12 changed files with 636 additions and 20 deletions
+36
View File
@@ -299,5 +299,41 @@ can see which secrets are currently injected.
See [How your secrets reach a workspace](#how-your-secrets-reach-a-workspace)
for what happens to running workspaces when you delete a secret.
## Import secrets from a file
If you keep secrets in a dotenv file, a flat JSON object, or a flat YAML
mapping, you can import the whole file instead of creating each secret
individually:
1. Go to the [**Secrets** page](#manage-secrets-from-the-dashboard) and select
**Add secret**.
1. Drop or select a `.env`, `.json`, `.yaml`, or `.yml` file in the upload
area. Coder imports the file as soon as you choose it.
Every key in the file becomes a secret. For example, this dotenv file creates
two secrets, `API_KEY` and `DATABASE_URL`, each injected as an environment
variable of the same name:
```sh
API_KEY=abc123
DATABASE_URL=postgres://user:pass@db.internal/app
```
In JSON and YAML files, every value must be a string. Quote numeric and
boolean values, for example `"PORT": "8080"`.
The import is all or nothing. If any entry fails validation, conflicts with
an existing secret, or exceeds a [limit](#limits), Coder cancels the import
and creates no secrets. The file must also be 1 MiB or smaller and contain no
more than 50 keys.
Keys that are not valid environment variable names, such as `MY-TOKEN` or the
reserved name `PATH`, are imported without an environment variable target.
They are not injected into workspaces until you add a valid environment
variable or file target.
To import secrets programmatically, use the
[Secrets API](../reference/api/secrets.md#import-user-secrets-from-a-file).
For full command details, see [`coder secret`](../reference/cli/secret.md) and
the [Secrets API reference](../reference/api/secrets.md).