Local Secrets
During local development, tsdevstack stores secrets in JSON files and provides them to services through a consistent interface. This page covers how to work with secrets in your local environment.
The Secrets Files
After running npx tsdevstack generate-secrets, you will have these files in your project root:
All of these files are gitignored. The per-app .env files are generated by generate-secrets so that tools like Prisma CLI and Next.js can read environment variables directly. Backend services should still use SecretsService at runtime — the .env files exist for CLI tools (e.g., npx prisma studio) and frontend builds.
Adding Your Own Secrets
To add a custom secret, edit .secrets.user.json:
Then regenerate:
The secrets object at the top level defines the values. The service sections specify which services receive which secrets.
Overriding Framework Defaults
You can override any framework-generated value by adding it to your user file:
Your values always take precedence over framework defaults.
Accessing Secrets in Backend Services
Backend services (NestJS) use the SecretsService to access secrets. Never use process.env directly.
This pattern ensures your code works the same way locally and in production.
Accessing Secrets in Frontend (Next.js)
Frontend applications receive secrets through generated .env files. Access them via process.env:
To add a secret to your frontend, update .secrets.user.json:
Accessing Secrets in SPAs (Rsbuild)
SPAs receive secrets through generated .env files (created by generate-secrets based on your secrets configuration) and expose them via build configuration:
Configure which env vars are bundled in your rsbuild.config.js:
Security note: Any secret exposed to an SPA is visible in the browser. Only expose values that are safe to be public, like API URLs.
Common Workflows
Initial Setup
The sync command generates secrets, Kong configuration, and other required files.
Adding a New Third-Party Service
- Add the API key to
.secrets.user.json:
- Regenerate and restart:
- Access in your service:
Troubleshooting
"SECRETS_PROVIDER not set"
Run npx tsdevstack generate-secrets to create the necessary files.
Secret Not Available in Service
- Check that the secret is defined in the
secretsobject in.secrets.user.json - Check that the service lists the secret in its
secretsarray - Regenerate with
npx tsdevstack generate-secrets - Restart the service
Changes Not Taking Effect
After modifying .secrets.user.json:
- Run
npx tsdevstack generate-secrets - Wait up to 1 minute for the cache to refresh (SecretsService has a 1-minute TTL)
Note: Backend services using SecretsService automatically reload secrets from the file when the cache expires. Restarting is only needed if you're using process.env directly (which you shouldn't in backend services).