Secret Groups & Lifecycle
Groups help you organize secrets and restrict which credentials are exposed to specific processes, tools, or subprocesses.
How Groups Work
Secrets can be assigned to groups in two ways:
- Inline Assignment: Declaring
groups = ["group-name"]directly within a variable definition ([vars.MY_SECRET]). - Explicit Group Blocks: Grouping secrets under
[groups.group-name.vars]with optional aliasing (as = "ALIAS").
Filtering at Runtime
When executing commands or exporting variables, you can filter secrets by group using the -g / --group flag:
# Load only secrets assigned to the 'backend' group
anzen run -g backend -- npm run start
# Export only shell-group variables
anzen export -g shell
If no groups are specified, Anzen filters for variables that do not belong to any group.