Skip to content

Config Vars & Secrets ​

Keel stores application configuration and secrets as encrypted SecureString values in AWS Systems Manager Parameter Store. Values are scoped by environment at /keel/<app>/<env>/<key> and injected through ECS task definitions.

bash
# Set one or more variables
keel config set DATABASE_POOL_SIZE=20 LOG_LEVEL=info

# Read a value
keel config get LOG_LEVEL

# List all variables for the current environment (values are never printed)
keel config list

# Remove variables
keel config unset LOG_LEVEL

keel config list includes the AWS-managed DATABASE_* variables injected from the RDS secret. You cannot use set, get, or unset on these managed names because AWS generates and rotates their values. Use keel db credentials to read them; see Database Credentials.

To expose a variable to your containers, list its key under the service's secrets: in keel.yml and run keel up to update the task definitions:

yaml
secrets:                  # added to every service
  - SECRET_KEY_BASE
services:
  worker:
    secrets:              # or per service
      - WORKER_API_TOKEN

Because config is environment-scoped, keel config set in staging does not affect production.

Database and cache variables ​

The top-level database and cache add-ons give every service their network rules plus these variables:

VariableSource
DATABASE_HOST, DATABASE_PORT, DATABASE_NAMEthe instance or cluster
DATABASE_USER, DATABASE_PASSWORDindividual keys of the RDS-managed secret
DATABASE_CREDENTIALSthat secret's whole JSON value
DATABASE_SCHEMEpostgres or mysql2, matching the engine
CACHE_HOST, CACHE_PORT, CACHE_TLSthe replication group
CACHE_URL, REDIS_URLa complete rediss://host:6379 URL

Keel injects DATABASE_USER and DATABASE_PASSWORD as separate ECS secrets in addition to the JSON document, so applications can construct a DATABASE_URL directly:

ruby
# config/database.yml
production:
  url: <%= "#{ENV['DATABASE_SCHEME']}://#{ENV['DATABASE_USER']}:#{ENV['DATABASE_PASSWORD']}@#{ENV['DATABASE_HOST']}:#{ENV['DATABASE_PORT']}/#{ENV['DATABASE_NAME']}" %>

The cache endpoint is TLS-only

Keel enables encryption in transit. Use CACHE_URL or REDIS_URL, which include the required rediss:// scheme.

database.name and database.username default to keeldb and keeluser; set them explicitly when an existing application expects different names.

Keel — the missing platform layer for AWS.