Secret Types
Harness supports two types of secrets; Text Secrets for inline string values and File Secrets for uploaded file content. Both are encrypted and can be stored in the built-in or any external secret man
Harness supports two types of secrets: Text Secrets for inline string values and File Secrets for uploaded file content. Both types are encrypted and can be stored in the built-in or any external secret manager.
Text secrets
Text secrets store inline string values such as passwords, tokens, and API keys. The value is provided directly as a string when creating the secret.
Common uses: API keys and access tokens, database passwords and connection strings, OAuth client secrets and refresh tokens, private keys stored as PEM-encoded strings, configuration values that must remain confidential.
Maximum size
50 MB
Encoding
UTF-8
Multi-line support
Yes, newlines and whitespace are preserved
Type identifier
SecretText
Examples
# API Token <a href="#api-token" id="api-token"></a>
# Type: SecretText <a href="#type-secrettext" id="type-secrettext"></a>
# Name: GitHub API Token <a href="#name-github-api-token" id="name-github-api-token"></a>
# ID: github_api_token <a href="#id-githubapitoken" id="id-githubapitoken"></a>
# Value: ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx <a href="#value-ghpxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" id="value-ghpxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"></a># Database Password <a href="#database-password" id="database-password"></a>
# Type: SecretText <a href="#type-secrettext" id="type-secrettext"></a>
# Name: Production DB Password <a href="#name-production-db-password" id="name-production-db-password"></a>
# ID: prod_db_password <a href="#id-proddbpassword" id="id-proddbpassword"></a>
# Value: S3cur3P@ssw0rd!2026 <a href="#value-s3cur3pssw0rd2026" id="value-s3cur3pssw0rd2026"></a>File secrets
File secrets store the content of uploaded files. The file is read, base64-encoded, and stored as an encrypted value. At runtime, the file content is decoded and made available to the pipeline execution.
Common uses: GCP service account JSON key files, Kubernetes kubeconfig files, TLS/SSL certificate and private key PEM files, license files and configuration bundles.
Maximum size
50 MB
File types
Any file type (.json, .yaml, .pem, .p12, .key, .txt, etc.)
Storage format
Base64-encoded
Type identifier
SecretFile
Examples
External secret managers
Harness integrates with external secret management platforms, allowing you to leverage your existing secrets infrastructure. When an external secret manager is configured, Harness stores only a reference to the secret path; the actual value remains in your infrastructure.
Supported platforms
HashiCorp Vault
Token, AppRole, AWS IAM, Kubernetes
Dynamic secrets, leasing, namespaces
AWS Secrets Manager
Access Key, IAM Role, IRSA
Automatic rotation, cross-account access
GCP Secret Manager
Service Account Key, Workload Identity
Versioning, IAM policies, replication
Azure Key Vault
Client Secret, Managed Identity
HSM-backed keys, soft-delete, purge protection
Custom
Shell script on Delegate
Any secret manager accessible from the Delegate
Configuration steps
Navigate to Account Settings → Connectors → Secret Managers.
Select the external secret manager type you want to configure.
Provide the connection details: endpoint URL, authentication credentials, and any platform-specific settings.
Test the connection to verify that Harness can reach your secret manager.
Save the configuration. The secret manager is now available for use when creating secrets.
Benefits
Secrets remain in your infrastructure: Harness never stores the actual secret value. Only a reference to the path in your secret manager is persisted.
Existing rotation policies apply: Continue using your organization's existing rotation schedules and automation. Harness resolves the latest value at execution time.
Data residency compliance: Secret values remain in the region and infrastructure where your secret manager is deployed, satisfying data residency requirements.
DELEGATE REQUIRED
External secret managers require a Harness Delegate with network access to the secret manager endpoint. Ensure the Delegate can resolve the secret manager hostname and that the required ports are open in your network configuration.
Last updated
Was this helpful?