Automated syncs
Push secrets to GitHub Actions or Vercel, and auto-spawn ephemeral preview environments from Git.
vaultic push
Sync an environment's secrets outward to a third-party target, on demand.
push github
Pushes to GitHub Actions repo (or repo-environment) secrets, using GitHub's public-key sodium-sealed-box encryption before writing.
| Flag | Description |
|---|---|
-e, --env <environment> | |
--owner <owner> | Required. GitHub org/user |
--repo <repo> | Required. GitHub repo name |
-ge, --gh-environment <name> | Push to a GitHub Environment's secrets instead of repo-level |
--token <token> | GitHub PAT (defaults to $GITHUB_TOKEN) |
-e/--env picks the Vaultic environment to read from; -ge/--gh-environment (optional) picks
a GitHub Environment to push into instead of repo-level secrets — these are two unrelated
namespaces that happen to both be called "environment," hence the intentionally different flags.
push vercel
| Flag | Description |
|---|---|
-e, --env <environment> | |
--project <projectId> | Required. |
--team <teamId> | For team-owned projects |
--target <target> | production | preview | development |
--token <token> | Vercel token (defaults to $VERCEL_TOKEN) |
Pushing to a cloud secret store (AWS/GCP/Azure) — either the same vaultic push <target> pattern,
or an always-on automatic version from the web app — has grown into its own page:
Cloud secret store sync
Push to AWS Secrets Manager, AWS SSM, GCP Secret Manager, or Azure Key Vault — on demand from the CLI, or automatically from the web app.
Ephemeral preview environments
vaultic git-integration <subcommand> configures the inbound Git webhook that auto-spawns/tears
down ephemeral preview environments: pushes to branches matching a pattern (default preview/*)
spawn or renew a preview-<branch-suffix> environment (inheriting a template environment until
overridden); deleting the branch tears it down immediately. A background job also expires any
ephemeral environment past its TTL.
git-integration setup
| Flag | Description |
|---|---|
--owner <owner> | Required. |
--repo <repo> | Required. |
--branch-pattern <pattern> | Glob with one *, e.g. preview/* |
--template <environment> | Environment new preview environments inherit unset keys from |
--ttl-days <days> | Days a preview environment lives before auto-expiring (server default: 7) |
Prints the webhook URL and HMAC secret to paste into GitHub (Settings → Webhooks — content
type application/json; enable the "Branches or tags" push event and "Branch or tag deletion").
git-integration show
Dumps the current Git integration config as raw JSON. No options.
git-integration remove
Removes the Git integration. No options.
Web app: Config Syncs
The dashboard view for the Git integration and per-environment automatic cloud sync.
Workload identity
Let CI jobs and pods authenticate with the OIDC identity their runtime already gives them — no static Vaultic token anywhere.
Cloud secret store sync
Push secrets to AWS Secrets Manager, AWS SSM Parameter Store, GCP Secret Manager, or Azure Key Vault — on demand from the CLI, or automatically from the web app.