Skip to main content

Environment Variables

Configure environment variables for template access and build customization

Config-defined variables

Define custom environment variables in your config's top-level env field:

env:
  MY_VAR: "some_value"
  BUILD_TYPE: "release"

These are available in templates as {{ Env.MY_VAR }} and are set in the environment for all external commands (cargo, docker, nfpm, etc.).

Per-target build environment

Set environment variables for specific build targets:

crates:
  - name: myapp
    builds:
      - binary: myapp
        env:
          x86_64-unknown-linux-gnu:
            CC: "gcc"
            OPENSSL_DIR: "/usr/local/ssl"
          aarch64-unknown-linux-gnu:
            CC: "aarch64-linux-gnu-gcc"

Standard environment variables

Anodizer respects these environment variables:

VariableDescription
ANODIZER_GITHUB_TOKENGitHub API token (takes precedence over GITHUB_TOKEN)
GITHUB_TOKENGitHub API token for releases and publishing
CARGO_REGISTRY_TOKENToken for crates.io publishing
DOCKER_USERNAME / DOCKER_PASSWORDDocker registry credentials

GitHub release upload tuning

VariableTypeDefaultDescription
ANODIZER_GITHUB_UPLOAD_CONCURRENCYu324Cap on parallel asset uploads to a release (applies to every forge: GitHub, GitLab, Gitea; the GITHUB infix is historical). Override of release.upload_concurrency:. Keep low (≤8) to avoid GitHub's secondary rate limit when releases include many artifacts.
ANODIZER_GITHUB_UPLOAD_PACE_MSinteger milliseconds200Proactive minimum interval between successive asset-upload starts on any forge, jittered ±20% and layered on top of the concurrency cap and the reactive backoff. Override of release.upload_pace:. Smooths the initial burst that trips GitHub's secondary rate limit. Set to 0 to disable pacing (rely on the cap + backoff).
ANODIZER_GITHUB_SECONDARY_RL_DELAY_SECSinteger seconds60Sleep duration after a GitHub secondary rate-limit response (403/429 carrying the "secondary rate limit" marker in the body or secondary-rate-limits in the documentation_url). Applied with ±20% jitter before the next upload retry.

Secret redaction in log output

Anodizer masks secret values in everything it prints: status lines, the -v command echoes, a subprocess's streamed output and error text. A masked value is replaced with $ and the name of the variable that holds it. The variables it reads are the process environment, the config's env: block, and the env: of the job whose command is running (a signs:, dockers:, sboms:, publishers: or build entry).

A variable is treated as a secret when its value is not empty and either rule holds:

RuleMatches
The name, compared without case, ends in _KEY, _SECRET, _PASSWORD, _TOKEN or _PASSPHRASE, or contains CREDENTIAL or APIKEY, and the value is not one of true, false, yes, no, on, off, 0, 1GITHUB_TOKEN, COSIGN_PASSWORD, GOOGLE_CREDENTIALS_JSON
The value starts with a known token prefix, whatever the name: sk-, ghp_, ghs_, gho_, ghu_, github_pat_, dckr_pat_, glpat-, AIza, ya29., xoxDEPLOY=ghp_…

Where a secret value is masked depends on its length:

Value lengthMasked
8 characters or moreevery occurrence, including inside a longer word (-p<value>)
under 8 charactersonly where it stands alone, not inside a longer word

Credentials written inside a URL (https://user:pass@host) are replaced with <redacted> whatever variable they came from.

Two consequences follow from matching on the name:

signs:
  - env:
      - COSIGN_KEY=cosign.key        # name ends in _KEY: the path is masked
      - REGISTRY_AUTH=hunter2hunter2 # plain name, no known prefix: NOT masked
Argument the command was givenPrinted as
--key=cosign.key--key=$COSIGN_KEY
--password=hunter2hunter2--password=hunter2hunter2

A file path or any other harmless value stored under a secret-shaped name prints as $NAME, and a real secret stored under a name that matches no rule is printed as it is. Name the variable that holds a secret with one of the suffixes above.

Template access

All environment variables (both config-defined and inherited from the shell) are accessible in templates:

name_template: "{{ ProjectName }}-{{ Env.BUILD_NUMBER }}"