Appearance
Config Vars & Secrets
Keel stores application configuration and secrets as encrypted SecureString values in AWS Systems Manager Parameter Store. Values are scoped by environment at /keel/<app>/<env>/<key> and injected through ECS task definitions.
bash
# Set one or more variables
keel config set DATABASE_POOL_SIZE=20 LOG_LEVEL=info
# Read a value
keel config get LOG_LEVEL
# List all variables for the current environment (values are never printed)
keel config list
# Remove variables
keel config unset LOG_LEVELkeel config list includes the AWS-managed DATABASE_* variables injected from the RDS secret. You cannot use set, get, or unset on these managed names because AWS generates and rotates their values. Use keel db credentials to read them; see Database Credentials.
To expose a variable to your containers, list its key under the service's secrets: in keel.yml and run keel up to update the task definitions:
yaml
secrets: # added to every service
- SECRET_KEY_BASE
services:
worker:
secrets: # or per service
- WORKER_API_TOKENBecause config is environment-scoped, keel config set in staging does not affect production.
Database and cache variables
The top-level database and cache add-ons give every service their network rules plus these variables:
| Variable | Source |
|---|---|
DATABASE_HOST, DATABASE_PORT, DATABASE_NAME | the instance or cluster |
DATABASE_USER, DATABASE_PASSWORD | individual keys of the RDS-managed secret |
DATABASE_CREDENTIALS | that secret's whole JSON value |
DATABASE_SCHEME | postgres or mysql2, matching the engine |
CACHE_HOST, CACHE_PORT, CACHE_TLS | the replication group |
CACHE_URL, REDIS_URL | a complete rediss://host:6379 URL |
Keel injects DATABASE_USER and DATABASE_PASSWORD as separate ECS secrets in addition to the JSON document, so applications can construct a DATABASE_URL directly:
ruby
# config/database.yml
production:
url: <%= "#{ENV['DATABASE_SCHEME']}://#{ENV['DATABASE_USER']}:#{ENV['DATABASE_PASSWORD']}@#{ENV['DATABASE_HOST']}:#{ENV['DATABASE_PORT']}/#{ENV['DATABASE_NAME']}" %>The cache endpoint is TLS-only
Keel enables encryption in transit. Use CACHE_URL or REDIS_URL, which include the required rediss:// scheme.
database.name and database.username default to keeldb and keeluser; set them explicitly when an existing application expects different names.