Skip to Content
DeploymentConfiguration and key rotation

Developer reference

Configuration and key rotation

Rotate credentials without leaking them or confusing API-token access with browser sessions.

Public project URL/key and public origins can appear in browser assets. Service-role credentials, worker secrets, housekeeping secrets and API tokens must stay server-side.

Rotate a server secret

  1. Create or configure the replacement through the owning provider.
  2. Update only the intended deployment environment.
  3. Redeploy or restart where the value is read at build/start time.
  4. Verify a bounded authorized operation with the replacement.
  5. Retire the old secret once its outstanding work is accounted for.

Coordinate worker calls that may still be using an old credential. Do not log either secret to prove the rotation.

Replace a Helm API token

Revoke an exposed token and create a replacement with minimum scopes. Update its integration and verify the intended request. Browser sign-out does not revoke every API token.

Change public origins

Update the app/docs origin pair and provider redirects together. Public origin variables require fresh browser assets. Review canonical metadata and auth links after publishing.

Check the real outcome

A variable being present does not prove a credential is valid or a provider service works. Exercise the affected flow and retain sanitized statuses or request identifiers.

Keep secrets out of Git, docs, shell transcripts and support screenshots. Use environment reference, token management and troubleshooting.