# Config Vars & Secrets

Keel stores application configuration and secrets as encrypted `SecureString` values in AWS Systems Manager Parameter Store. Values are scoped by environment at `/keel/<app>/<env>/<key>` and injected through ECS task definitions.

```bash
# Set one or more variables
keel config set DATABASE_POOL_SIZE=20 LOG_LEVEL=info

# Read a value
keel config get LOG_LEVEL

# List all variables for the current environment (values are never printed)
keel config list

# Remove variables
keel config unset LOG_LEVEL
```

`keel config list` includes the AWS-managed `DATABASE_*` variables injected from the RDS secret. You cannot use `set`, `get`, or `unset` on these managed names because AWS generates and rotates their values. Use `keel db credentials` to read them; see [Database Credentials](../database-credentials).

To expose a variable to your containers, list its key under the service's `secrets:` in `keel.yml` and run `keel up` to update the task definitions:

```yaml
secrets:                  # added to every service
  - SECRET_KEY_BASE
services:
  worker:
    secrets:              # or per service
      - WORKER_API_TOKEN
```

Because config is environment-scoped, `keel config set` in `staging` does not affect `production`.

## Database and cache variables

The top-level `database` and `cache` add-ons give every service their network rules plus these variables:

| Variable | Source |
|---|---|
| `DATABASE_HOST`, `DATABASE_PORT`, `DATABASE_NAME` | the instance or cluster |
| `DATABASE_USER`, `DATABASE_PASSWORD` | individual keys of the RDS-managed secret |
| `DATABASE_CREDENTIALS` | that secret's whole JSON value |
| `DATABASE_SCHEME` | `postgres` or `mysql2`, matching the engine |
| `CACHE_HOST`, `CACHE_PORT`, `CACHE_TLS` | the replication group |
| `CACHE_URL`, `REDIS_URL` | a complete `rediss://host:6379` URL |

Keel injects `DATABASE_USER` and `DATABASE_PASSWORD` as separate ECS secrets in addition to the JSON document, so applications can construct a `DATABASE_URL` directly:

```ruby
# config/database.yml
production:
  url: <%= "#{ENV['DATABASE_SCHEME']}://#{ENV['DATABASE_USER']}:#{ENV['DATABASE_PASSWORD']}@#{ENV['DATABASE_HOST']}:#{ENV['DATABASE_PORT']}/#{ENV['DATABASE_NAME']}" %>
```

**The cache endpoint is TLS-only**
Keel enables encryption in transit. Use `CACHE_URL` or `REDIS_URL`, which include the required `rediss://` scheme.

`database.name` and `database.username` default to `keeldb` and `keeluser`; set them explicitly when an existing application expects different names.
