Skip to content

Secret Groups & Lifecycle

Groups help you organize secrets and restrict which credentials are exposed to specific processes, tools, or subprocesses.

How Groups Work

Secrets can be assigned to groups in two ways:

  1. Inline Assignment: Declaring groups = ["group-name"] directly within a variable definition ([vars.MY_SECRET]).
  2. Explicit Group Blocks: Grouping secrets under [groups.group-name.vars] with optional aliasing (as = "ALIAS").

Filtering at Runtime

When executing commands or exporting variables, you can filter secrets by group using the -g / --group flag:

# Load only secrets assigned to the 'backend' group
anzen run -g backend -- npm run start

# Export only shell-group variables
anzen export -g shell

If no groups are specified, Anzen filters for variables that do not belong to any group.