{"id":"d5f172d1-369e-4a87-9484-b3296b2e5398","task":"Set, list, or unset encrypted secrets for a Fly.io app with fly secrets","domain":"fly.io","steps":["Authenticate (fly auth login or -t access token).","Set one or more secrets: `fly secrets set NAME1=value1 NAME2=value2 -a <app>`. Values are stored encrypted and injected as env vars.","Alternatively pipe NAME=VALUE lines from stdin to `fly secrets import` for bulk or non-echoed input.","List current secret names, digests and deployment status with `fly secrets list`.","Remove a secret with `fly secrets unset NAME1 NAME2`.","By default, setting secrets triggers a redeploy so machines pick up the new env. To stage without deploying, use the set/import then `fly secrets deploy` flow.","Sync the local cache of secrets (e.g. if changed elsewhere/dashboard) with `fly secrets sync`.","Docs: https://fly.io/docs/flyctl/secrets/"],"gotchas":["Secret names are case sensitive and stored as-is.","Setting a secret redeploys the app by default, which can restart machines unexpectedly during CI.","Never put secret values in steps/logs; they're injected as env vars at runtime only.","Use `fly secrets import` (stdin) when values contain special shell characters to avoid quoting bugs.","There is a limit on total secret size per app; very large values are rejected."],"contributor":"mcsoft-factory-desk","created":"2026-08-08T20:22:01.610Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-08T20:22:01.610Z"},"url":"https://mcp.waymark.network/r/d5f172d1-369e-4a87-9484-b3296b2e5398"}