For the complete documentation index, see llms.txt. This page is also available as Markdown.

Secret Types

Harness supports two types of secrets; Text Secrets for inline string values and File Secrets for uploaded file content. Both are encrypted and can be stored in the built-in or any external secret man

Harness supports two types of secrets: Text Secrets for inline string values and File Secrets for uploaded file content. Both types are encrypted and can be stored in the built-in or any external secret manager.

Text secrets

Text secrets store inline string values such as passwords, tokens, and API keys. The value is provided directly as a string when creating the secret.

Common uses: API keys and access tokens, database passwords and connection strings, OAuth client secrets and refresh tokens, private keys stored as PEM-encoded strings, configuration values that must remain confidential.

Property
Value

Maximum size

50 MB

Encoding

UTF-8

Multi-line support

Yes, newlines and whitespace are preserved

Type identifier

SecretText

Examples

# API Token <a href="#api-token" id="api-token"></a>
# Type: SecretText <a href="#type-secrettext" id="type-secrettext"></a>
# Name: GitHub API Token <a href="#name-github-api-token" id="name-github-api-token"></a>
# ID: github_api_token <a href="#id-githubapitoken" id="id-githubapitoken"></a>
# Value: ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx <a href="#value-ghpxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" id="value-ghpxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"></a>
# Database Password <a href="#database-password" id="database-password"></a>
# Type: SecretText <a href="#type-secrettext" id="type-secrettext"></a>
# Name: Production DB Password <a href="#name-production-db-password" id="name-production-db-password"></a>
# ID: prod_db_password <a href="#id-proddbpassword" id="id-proddbpassword"></a>
# Value: S3cur3P@ssw0rd!2026 <a href="#value-s3cur3pssw0rd2026" id="value-s3cur3pssw0rd2026"></a>

File secrets

File secrets store the content of uploaded files. The file is read, base64-encoded, and stored as an encrypted value. At runtime, the file content is decoded and made available to the pipeline execution.

Common uses: GCP service account JSON key files, Kubernetes kubeconfig files, TLS/SSL certificate and private key PEM files, license files and configuration bundles.

Property
Value

Maximum size

50 MB

File types

Any file type (.json, .yaml, .pem, .p12, .key, .txt, etc.)

Storage format

Base64-encoded

Type identifier

SecretFile

BASE64 ENCODING

Harness converts file secrets to base64-encoded text when storing them. When you retrieve a file secret in a pipeline, you may need to decode it before use. Go to Managing Secrets section for decoding examples.

Examples


External secret managers

Harness integrates with external secret management platforms, allowing you to leverage your existing secrets infrastructure. When an external secret manager is configured, Harness stores only a reference to the secret path; the actual value remains in your infrastructure.

Supported platforms

Platform
Authentication Methods
Features

HashiCorp Vault

Token, AppRole, AWS IAM, Kubernetes

Dynamic secrets, leasing, namespaces

AWS Secrets Manager

Access Key, IAM Role, IRSA

Automatic rotation, cross-account access

GCP Secret Manager

Service Account Key, Workload Identity

Versioning, IAM policies, replication

Azure Key Vault

Client Secret, Managed Identity

HSM-backed keys, soft-delete, purge protection

Custom

Shell script on Delegate

Any secret manager accessible from the Delegate

Configuration steps

  1. Navigate to Account Settings → Connectors → Secret Managers.

  2. Select the external secret manager type you want to configure.

  3. Provide the connection details: endpoint URL, authentication credentials, and any platform-specific settings.

  4. Test the connection to verify that Harness can reach your secret manager.

  5. Save the configuration. The secret manager is now available for use when creating secrets.

Benefits

  • Secrets remain in your infrastructure: Harness never stores the actual secret value. Only a reference to the path in your secret manager is persisted.

  • Existing rotation policies apply: Continue using your organization's existing rotation schedules and automation. Harness resolves the latest value at execution time.

  • Data residency compliance: Secret values remain in the region and infrastructure where your secret manager is deployed, satisfying data residency requirements.

Last updated

Was this helpful?