Skip to main content
Version: 0.0.x

Secrets Management

This section covers all CLI commands for managing secrets used by your AI agents on Agent Cloud. Secrets allow you to securely store sensitive configuration values like API keys, database credentials, and registry authentication.

There are two types of secrets:

  • Environment secrets: key-value pairs injected as environment variables.
  • Image pull secrets: container registry credentials for pulling private images.

Environment Secrets​

Environment secrets are key-value pairs that are securely injected as environment variables into your agent containers at runtime.

List​

List all secret sets.

Usage​

videosdk agent secrets list

Example Output​

$ videosdk agent secrets list

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Listing Secrets
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

┌──────────────────┬─────────────────┬──────────┐
│ Name │ Secret ID │ Type │
├──────────────────┼─────────────────┼──────────┤
│ my-secrets │ sec-abc123 │ env │
│ prod-credentials │ sec-xyz789 │ env │
└──────────────────┴─────────────────┴──────────┘

✓ Secrets listed successfully

Create​

Create a new secret set.

Usage​

videosdk agent secrets create <name> [OPTIONS]

Options​

OptionShortDescriptionDefault
--file-fPath to .env file with key=value pairsNone (interactive mode)
--regionRegion for storing secretsNone

Example Output​

$ videosdk agent secrets create my-secrets --file .env

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Creating Secret
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Secret Name: my-secrets
File: .env

Secrets to be saved:
- API_KEY: ******
- DATABASE_URL: ******

Confirm action
❯ Save secrets
Cancel

Saving secrets...
Secrets saved successfully.

✓ Secret 'my-secrets' created successfully

Do you want to add this secret to videosdk.yaml? [y/N]: y
✓ Secret ID saved to videosdk.yaml: <secret-id>

videosdk.yaml Structure​

When saved to videosdk.yaml, the secret ID is added under the secrets section:

secrets:
env: <secret-id>

#### Examples

```bash
# Create from .env file
videosdk agent secrets create my-secrets --file .env

# Create interactively (will prompt for key-value pairs)
videosdk agent secrets create my-secrets

# Create with specific region
videosdk agent secrets create my-secrets --file .env --region in002

Add​

Add new keys to an existing secret set.

Usage​

videosdk agent secrets add <name>

Example Output​

$ videosdk agent secrets add my-secrets

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Adding to Secret
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Adding secret...
Enter key: NEW_API_KEY
Enter value: ********

Add another secret?
❯ Yes
No

Secrets to be saved:
- NEW_API_KEY: ******

Confirm action
❯ Save secrets
Cancel

Secret added successfully.

✓ Keys added to secret 'my-secrets' successfully

Remove​

Remove specific keys from a secret set.

Usage​

videosdk agent secrets remove <name>

Example Output​

$ videosdk agent secrets remove my-secrets

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Removing Keys from Secret
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Removing secret...
Enter key: OLD_API_KEY
Remove another key?
❯ Yes
No

Secret removed successfully.

Describe​

Show details of a secret set (keys only, values are hidden).

Usage​

videosdk agent secrets describe <name>

Example Output​

$ videosdk agent secrets describe my-secrets

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Describing Secret
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Name my-secrets
Secret ID sec-abc123
Type env

┌──────────────────┬──────────┐
│ Key │ Value │
├──────────────────┼──────────┤
│ OPENAI_API_KEY │ ****** │
│ DATABASE_URL │ ****** │
│ SECRET_TOKEN │ ****** │
└──────────────────┴──────────┘

Delete​

Permanently delete a secret set.

Usage​

videosdk agent secrets delete <name>

Example Output​

$ videosdk agent secrets delete my-secrets

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Deleting Secret
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

✓ Secret 'my-secrets' deleted successfully
caution

This action is permanent and cannot be undone. All keys in the secret set will be deleted.

Image Pull Secrets​

Image pull secrets store container registry credentials, allowing Agent Cloud to pull images from private registries.

Create Image Pull Secret​

Create an image pull secret for private container registries.

Usage​

videosdk agent image-pull-secret <name> [OPTIONS]

Arguments​

ArgumentRequiredDescription
nameYesName for the image pull secret

Options​

OptionShortRequiredDescriptionDefault
--serverYesRegistry server URL—
--username-uYesRegistry username—
--password-pYesRegistry password or access token—
--regionNoDeployment region for the secretus002

What Happens​

  1. The CLI validates the required registry details provided via flags.
  2. Credentials are securely stored and can be referenced in deployments.
  3. Automatic Configuration: The CLI prompts you to save the secret to your videosdk.yaml file. If confirmed, the secret name is automatically added under the secrets section.

Example Output​

✓ Image pull secret 'my-registry-secret' created successfully

Do you want to add this secret to videosdk.yaml? [y/N]: y
✓ Secret Name saved to videosdk.yaml: my-registry-secret

videosdk.yaml Structure​

secrets:
image-pull: my-registry-secret

Examples​

# ECR (AWS)
videosdk agent image-pull-secret my-ecr-secret \
--server 1234567890.dkr.ecr.ap-south-1.amazonaws.com \
-u AWS \
-p $(aws ecr get-login-password --region ap-south-1)

# ACR (Azure)
videosdk agent image-pull-secret my-acr-secret \
--server myregistry.azurecr.io \
-u myusername \
-p mypassword

# GCR (GCP)
videosdk agent image-pull-secret my-gcr-secret \
--server https://<REGION>-docker.pkg.dev \
-u _json_key \
-p "$(cat keyfile.json)" \
--region us002

# Docker Hub
videosdk agent image-pull-secret my-dockerhub-secret \
--server https://index.docker.io/v1/ \
-u myusername \
-p mypassword \
--region us002

Using Secrets in Deployments​

Once you've created secrets, you can reference them when deploying your agent:

note

In examples like myrepo/myagent:v1, myrepo is a placeholder for your Docker registry username (e.g., your Docker Hub username). Replace it with your actual username.

Environment Secrets​

videosdk agent deploy --image myrepo/myagent:v1 --env-secret my-secrets

Image Pull Secrets​

videosdk agent deploy --image ghcr.io/myorg/myagent:v1 --image-pull-secret ghcr-secret

Combined Example​

videosdk agent deploy \
--image ghcr.io/myorg/myagent:v1 \
--env-secret prod-credentials \
--image-pull-secret ghcr-secret \
--min-replica 2 \
--max-replica 10

Quick Reference​

CommandDescription
videosdk agent secrets listList all secret sets
videosdk agent secrets create <name>Create a new secret set
videosdk agent secrets add <name>Add keys to a secret
videosdk agent secrets remove <name>Remove keys from a secret
videosdk agent secrets describe <name>Show secret details
videosdk agent secrets delete <name>Delete a secret set
videosdk agent image-pull-secret <name>Create registry credentials

Best Practices​

  1. Use .env files for bulk creation: When you have many secrets, create a .env file and use --file .env

  2. Separate secrets by environment: Create different secret sets for development, staging, and production

  3. Rotate secrets regularly: Delete and recreate secrets periodically for security

  4. Use descriptive names: Name your secrets clearly (e.g., prod-api-keys, staging-db-creds)

Got a Question? Ask us on discord