Vaultic
Integrations

Automated syncs

Push secrets to GitHub Actions or Vercel, and auto-spawn ephemeral preview environments from Git.

vaultic push

Sync an environment's secrets outward to a third-party target, on demand.

push github

Pushes to GitHub Actions repo (or repo-environment) secrets, using GitHub's public-key sodium-sealed-box encryption before writing.

FlagDescription
-e, --env <environment>
--owner <owner>Required. GitHub org/user
--repo <repo>Required. GitHub repo name
-ge, --gh-environment <name>Push to a GitHub Environment's secrets instead of repo-level
--token <token>GitHub PAT (defaults to $GITHUB_TOKEN)

-e/--env picks the Vaultic environment to read from; -ge/--gh-environment (optional) picks a GitHub Environment to push into instead of repo-level secrets — these are two unrelated namespaces that happen to both be called "environment," hence the intentionally different flags.

push vercel

FlagDescription
-e, --env <environment>
--project <projectId>Required.
--team <teamId>For team-owned projects
--target <target>production | preview | development
--token <token>Vercel token (defaults to $VERCEL_TOKEN)

Pushing to a cloud secret store (AWS/GCP/Azure) — either the same vaultic push <target> pattern, or an always-on automatic version from the web app — has grown into its own page:

Cloud secret store sync

Push to AWS Secrets Manager, AWS SSM, GCP Secret Manager, or Azure Key Vault — on demand from the CLI, or automatically from the web app.

Ephemeral preview environments

vaultic git-integration <subcommand> configures the inbound Git webhook that auto-spawns/tears down ephemeral preview environments: pushes to branches matching a pattern (default preview/*) spawn or renew a preview-<branch-suffix> environment (inheriting a template environment until overridden); deleting the branch tears it down immediately. A background job also expires any ephemeral environment past its TTL.

git-integration setup

FlagDescription
--owner <owner>Required.
--repo <repo>Required.
--branch-pattern <pattern>Glob with one *, e.g. preview/*
--template <environment>Environment new preview environments inherit unset keys from
--ttl-days <days>Days a preview environment lives before auto-expiring (server default: 7)

Prints the webhook URL and HMAC secret to paste into GitHub (Settings → Webhooks — content type application/json; enable the "Branches or tags" push event and "Branch or tag deletion").

git-integration show

Dumps the current Git integration config as raw JSON. No options.

git-integration remove

Removes the Git integration. No options.

Web app: Config Syncs

The dashboard view for the Git integration and per-environment automatic cloud sync.

On this page