Secrets
Workers often need credentials, for example a token for an external API. Managed deployments read them from the workspace Secrets Manager: you bind a workspace secret to an environment variable, and the worker reads the value from its environment at boot. Only secrets from the deployment's workspace can be bound.
Bind a workspace secret to your deployment:
# /// script
# dependencies = [
# "mistralai>=3.0",
# ]
# ///
import os
from mistralai.client import Mistral
client = Mistral(api_key=os.environ["MISTRAL_API_KEY"])
deployment = client.workflows.deployments.update_deployment(
name="<your-deployment-name>",
spec={
"backend_spec": {
"secrets": [
{
"env_var_name": "GITHUB_TOKEN",
"reference": "secret:workspace:github_token",
}
],
}
},
)
print(deployment.name)Changing a secret's value does not restart the worker automatically. The worker keeps the value it read at boot. For now, restart the deployment manually to pick up a new value.
Available at build and at runtime
A binding reaches the worker twice:
- At runtime, as an environment variable, read when the worker boots.
- At build time, as a Docker build arg with the same name. Declare a matching
ARGin theDockerfileto use it, for example to install packages from a private registry:
ARG UV_INDEX_USERNAME
ARG UV_INDEX_PASSWORD
RUN uv sync --frozen --no-devBuild args are stored in the image's history and layers, so anyone who can access the image can recover the values. Prefer credentials you can rotate, and avoid binding high-value secrets for builds.