Skip to main content
You can connect apps to databases, secrets, and other apps using environment references. Create the referenced resource first. Database fields are case-insensitive. URL is an alias for the connection string.

Pass References from the CLI or SDK

Single-quote references in shell commands so the shell passes them unchanged:
Secret and database references must fill the entire value. App URLs can include a suffix, such as ${{app.api.URL}}/health.

Generated Values

${{secret(32)}} generates a 32-character secret and reuses it on later deployments. The length can be 1–512; an optional second argument sets the alphabet. ${{randomInt(10, 100)}} generates an integer from 10 through 99. With no arguments, randomInt() uses 0–99.

Update an Existing App

Edit references in the dashboard, or use MCP’s set_env and connect_services tools. Both deploy a new version. update_secret takes effect on the next container start. For build-time secrets, use Image.with_secrets().