> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/continuous-delivery/use-continuous-delivery/cd-building-blocks/services/cd-services-config-files.md).

# Use config files in your deployments

Add plain text and encrypted configuration files to Harness CD services, reference them using expressions, and override them at the environment level.

You can add files to your Harness services and then reference and use those files in your service manifests, specifications, and pipelines. Files are added in the **Config Files** section of a Harness service and can be stored in the Harness file store or in a Git provider.

***

## What you will learn from this topic

* **Config file storage:** Where config files can be stored and what file types are supported.
* **Adding config files:** How to add plain text and encrypted config files to a CD service using YAML or Pipeline Studio.
* **Referencing config files:** How to use Harness expressions to reference config file contents in manifests and pipelines.
* **Overriding config files:** How to override service config files at the environment level for all services or for specific services.
* **Copying config files:** How to use the Copy command to deliver config files to target hosts.

***

## Config file capabilities

Config files can be stored in the following locations:

* **Harness file store:** All platform [integrations](/continuous-delivery/new-to-continuous-delivery/cd-integrations.md) (Kubernetes, etc.) support config files stored in the Harness [file store](/continuous-delivery/use-continuous-delivery/cd-building-blocks/services/add-inline-manifests-using-file-store.md).
* **Git providers:** You can use config files in any Git provider, including GitHub, GitLab, and Bitbucket. Connect to these providers using Harness connectors. Ensure that the connector credentials have read permissions on the target repository.

You can add plain or encrypted text files. Both types are referenced using a Harness expression:

* With a plain text config file, Harness renders the contents of the file.
* With an encrypted text config file, you need to base64 decode it before you can reference it within the deployment.

### Config file constraints

The following constraints apply when you use config files:

* Files must be 1MB or less.
* All text files are supported (JSON, TXT, XML, etc.).
* You cannot use Harness variables in an encrypted text config file.
* You cannot reference other config files within a config file.
* Config files cannot be binaries.

### Expressions are not allowed in config file references

Config files are referenced using the `<+configFile.getAsString("CONFIG_FILE_ID")>` format, as described in [Reference and encode config files](#reference-and-encode-config-files).

You cannot use Harness expressions in the parameter field of the `getAsString()` and `getAsBase64()` functions. For example, this expression fails: `<+configFile.getAsString("<+serviceVariable.var_name>")>`.

***

## Add config files to a service

You can add config files to any Harness service deployment type (Kubernetes, ECS, etc.).

{% tabs %}
{% tab title="YAML" %}
The following example shows a service with both a plain text and encoded config file added from the Harness file store.

```yaml
service:
  name: Config files
  identifier: Config_files
  tags: {}
  serviceDefinition:
    spec:
      configFiles:
        - configFile:
            identifier: plainText
            spec:
              store:
                type: Harness
                spec:
                  files:
                    - /Config files/my-plain-text-file.txt
        - configFile:
            identifier: encodedTextFile
            spec:
              store:
                type: Harness
                spec:
                  secretFiles:
                    - sshnov7
    type: Ssh
```

The encoded file is added as a [Harness secret](https://developer.harness.io/docs/platform/secrets/secrets-management/harness-secret-manager-overview). Create the secret separately if you are using YAML.

Use the `configFile.identifier` value to reference the config file.

You can attach multiple files to a config file. Add a new line for each additional file:

```yaml
                  files:
                    - /Config files/file1.json
                    - /dev/file2.json
```

{% endtab %}

{% tab title="Pipeline Studio" %}
To add a config file to a service in Pipeline Studio, do the following:

1. In the Harness service, in **Config Files**, select **Add Config File**.
2. In **Config File Source**, select **Harness**, then select **Continue**.
3. In **Config File Identifier**, enter a name for the file.
4. In **Select file type**, select **File Store** or **Encrypted**. Encrypted files are stored as [Harness secrets](https://developer.harness.io/docs/platform/secrets/secrets-management/harness-secret-manager-overview).
5. Select **Add** to attach multiple files as a single config file.
6. Select **Submit**.

Use the value you entered in **Config File Identifier** to reference the config file as an expression in the format `<+configFile.getAsString("CONFIG_FILE_ID")>`.
{% endtab %}
{% endtabs %}

### Multiple files in one config file

You can attach multiple files to one config file. All files must be either plain text or encoded. You cannot mix types.

***

## Reference and encode config files

Files added in the **Config Files** section of a service are referenced using the following Harness expressions:

* Plain text file contents: `<+configFile.getAsString("CONFIG_FILE_ID")>`
* Base64-encoded file contents: `<+configFile.getAsBase64("CONFIG_FILE_ID")>`

If the config file has multiple text or encrypted files attached, use the following fileStore or secrets variable expressions:

* `<+fileStore.getAsString("SCOPED_FILEPATH")>`
* `<+fileStore.getAsBase64("SCOPED_FILEPATH")>`
* `<+secrets.getValue("SCOPED_SECRET_ID")>`

The following are examples of each expression type:

* `<+configFile.getAsString("cf_file")>`
* `<+configFile.getAsBase64("cf_file")>`
* `<+fileStore.getAsString("/folder1/configFile")>`
* `<+fileStore.getAsBase64("account:/folder1/folder2/configFile")>`
* `<+secrets.getValue("account.MySecretFileIdentifier")>`

### Use Base64 to avoid new lines

If you are going to use a config file in a manifest or shell script, be aware that `<+configFile.getAsString()>` can cause problems by adding new lines to your manifest unless you format the file carefully.

Instead, use `<+configFile.getAsBase64()>`. This ensures that the contents of the file are rendered as a single line.

In a Shell Script step or service command, it looks like this:

```bash
echo <+configFile.getAsBase64("myFile")>
```

### Decode a config file in a manifest

In a Kubernetes manifest (in this example, a ConfigMap), you decode the base64 config file and indent it for the YAML syntax.

The following is the `values.yaml`:

```yaml
my_file:`my_file:\<+configFile.getAsBase64("myFile")>`
```

The following is the ConfigMap:

```yaml
data:  
  keyname: |  
{{.Values.my_file | b64dec | indent 4}}
```

At runtime, the config file is decoded and used as plaintext.

***

## Use Harness variables in config files

Plain text config files support the following [Harness variables](https://developer.harness.io/docs/platform/variables-and-expressions/harness-variables):

* Pipeline variables
* Service variables
* Environment variables
  * Environment override variables
* Secrets

{% hint style="info" %}
**Encrypted files do not support Harness variables**

You cannot use Harness variables in an encrypted text config file.
{% endhint %}

***

## Override service config files at the environment level

You can override service config files at the environment level. When the service is deployed to that environment, the environment's config files override the service's config files.

### Override config files for all services

To override the config files for all services used with an environment, do the following.

{% tabs %}
{% tab title="YAML" %}
The following example shows an environment with config file overrides in its **overrides**.

```yaml
environment:
  name: Config Files
  identifier: Config_Files
  tags: {}
  type: PreProduction
  orgIdentifier: default
  projectIdentifier: CD_Docs
  variables: []
  overrides:
    configFiles:
      - configFile:
          identifier: EnvironmentPlainText
          spec:
            store:
              type: Harness
              spec:
                files:
                  - /Config files/my-plain-text-file.txt
      - configFile:
          identifier: EnvironmentEncodedFile
          spec:
            store:
              type: Harness
              spec:
                secretFiles:
                  - account.Dpk
```

{% endtab %}

{% tab title="Pipeline Studio" %}
To add a config file override in Pipeline Studio, do the following:

1. In **Environments**, select an environment.
2. In the environment's **Configuration**, in **Config Files**, select **New Config File Override**.
3. Follow the same steps as when adding a config file in a service, then select **Submit**.
   {% endtab %}
   {% endtabs %}

### Override config files for specific services

You can override the config files of specific services deployed to an environment. To do so, complete the following steps:

1. In **Environments**, select an environment.
2. In the environment's **Service Overrides**, select **New configuration overrides**.
3. In **Service**, select the service to override.
4. In **Override Type**, select **Config file**, then select **New Config File Override**.
5. In **Config File Selection**, select the config file to override, then select **Override**.

![Config file override panel showing service override configuration](https://3694223630-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy1JhZ4oKIppwY7d5AhPj%2Fuploads%2Fgit-blob-a03897abd33d4884ffdc3e4760b08aac9ecdb49a%2Fconfig-file-override.png?alt=media)

6. Follow the steps to select the override file, then select **Submit**.

When the selected service is deployed to this environment, the environment's config files override that service's config files.

### Override priority for config files and variables

Harness supports [overriding service](/continuous-delivery/use-continuous-delivery/cd-building-blocks/environments/create-environments.md) config files at the environment level.

Config files are a black box that can contain multiple formats and content, such as YAML, JSON, and plain text. Consequently, they cannot be overridden like Values YAML files.

When you have config files at two or more of the following levels, the standard override priority is applied. The priority from top to bottom is:

1. Environment service overrides
2. Environment configuration
3. Service settings

![Override priority diagram showing environment service overrides taking precedence over environment configuration and service settings](https://3694223630-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy1JhZ4oKIppwY7d5AhPj%2Fuploads%2Fgit-blob-2c3b2640b96d9e1032fc2115840f128995fca807%2F9fbf54319fcbbfaf81732ede00d0e6226ea193524fd8fe61dae5ade93ec6fc71.png?alt=media)

When you have variables with the same name at two or more of the environment Service Overrides, Configuration, and the service itself, the same override priority applies.

***

## Copy config files to target hosts

In most cases, you can use the Copy command to copy config files to your target hosts.

{% tabs %}
{% tab title="YAML" %}
The following example shows a Command step that copies a config file to all target hosts.

```yaml
              - step:
                  type: Command
                  name: Copy
                  identifier: Copy
                  spec:
                    onDelegate: false
                    environmentVariables: []
                    outputVariables: []
                    commandUnits:
                      - identifier: Copy
                        name: Copy
                        type: Copy
                        spec:
                          sourceType: Config
                          destinationPath: /
                  timeout: 10m
                  failureStrategies: []
                  strategy:
                    repeat:
                      items: <+stage.output.hosts>
```

The `strategy.repeat.items: <+stage.output.hosts>` setting runs the command on all target hosts.
{% endtab %}

{% tab title="Pipeline Studio" %}
To copy a config file to target hosts using a Command step, do the following:

1. In your CD stage, add a **Command** step.
2. In the Command step, in **Run the following commands**, select **Add Command**.
3. In **Add Command**, in **Command Type**, select **Copy**.
4. In **Select file type to copy**, select **Config**.
5. In **Destination Path**, enter the path on the target host where you want the config file copied.
6. Select **Add**.
7. In the Command step **Advanced** settings, select **Looping Strategy**.
8. Select the **Repeat** strategy and enter the following:

```yaml
repeat:
  items: <+stage.output.hosts>
```

This runs the command on all target hosts.
{% endtab %}
{% endtabs %}

***

## Next steps

After you add and configure config files in your Harness services, manage overrides per environment or reference config files in your manifests and pipelines.

* [Add inline manifests using the file store](/continuous-delivery/use-continuous-delivery/cd-building-blocks/services/add-inline-manifests-using-file-store.md): Store and manage manifests and config files in the Harness file store.
* [Create environments](/continuous-delivery/use-continuous-delivery/cd-building-blocks/environments/create-environments.md): Configure environments and set up service-level config file overrides.
* [Harness variables reference](https://developer.harness.io/docs/platform/variables-and-expressions/harness-variables): Review the full list of Harness expressions you can use in plain text config files.
* [CD integrations](/continuous-delivery/new-to-continuous-delivery/cd-integrations.md): Review which deployment types support config files.

{% @harness-feedback/feedback %}
