Skip to content

GitHub Repo Secrets

This target upserts GitHub Actions repository secrets for a repo.

Terminal window
lazyenv targets create
Terminal window
lazyenv targets run ci
# CI-safe (no prompts). All values must exist as env vars.
lazyenv targets run ci --yes

lazyenv resolves a GitHub token in this order:

  1. LAZYENV_GITHUB_TOKEN
  2. GITHUB_TOKEN
  3. GH_TOKEN
  4. gh auth token (requires gh installed and authenticated)
  • Values are encrypted client-side using the repo public key.
  • Secret values come from env vars with the same name (for example DOPPLER_TOKEN).
  • For store-to-store fan-out, use a store target (see Targets).