Browse documentation
On this page

Peren documentation

Credentials and secrets

Choose Worker secret strings, provider environment variables, or minted tokens by what the call path actually checks.

Use the credential surface that matches who must see the value and which process checks it.

Worker secret string

Use a Worker secret when application code must read the value from env.

Declare the secret on the service. A missing resolved value fails the process before listeners open. The Worker receives a string. Rotate with Rotate secrets.

[services.secrets]
STRIPE_SECRET_KEY = { source = "store", name = "services/api/STRIPE_SECRET_KEY" }
export default {
  async fetch(request, env) {
    return fetch("https://api.stripe.com/v1/customers", {
      headers: { authorization: `Bearer ${env.STRIPE_SECRET_KEY}` },
    });
  },
};

A secrets-store binding also resolves to a string on env. Prefer one declared secret name per capability the Worker must call itself.

Provider environment variable

Use a provider environment variable when the node must hold a credential the Worker must not read.

Examples:

  • AWS SigV4 access_key_env, secret_key_env, and optional token_env for configured or environment credential sources. Signing runs in the node. The Worker cannot read the keys.
  • Client mTLS cert_pem_env and key_pem_env on type = "mtls_certificate". Pass the binding as fetch(url, { cf: { mtlsCertificate: env.NAME } }). The Worker cannot read the PEM.
  • Object-store, broker, AI, and vector provider credentials named by the provider configuration.

Do not copy those values into [services.secrets] unless the Worker itself must present them.

peren credential mint

Mint a scoped token when an operator or automation needs a signed tenant credential with an explicit bucket prefix and scopes.

peren credential mint ./credential-keys \
  --tenant acme \
  --bucket-prefix tenants/acme \
  --scope r2:read \
  --scopes r2:write

The command prints one token to stdout. The token expires 15 minutes after mint. Scopes must be non-empty ASCII tokens using letters, digits, and :, -, _, or ..

authorize exists for scope and bucket-prefix checks against a minted token. That check is not wired into the Worker request path. Do not treat a minted token as something Peren verifies on every R2 request.

peren credential node

Mint a node identity token when joining a node to the fleet registry.

peren credential node ./credential-keys \
  --cluster prod \
  --node 00000000-0000-0000-0000-000000000001 \
  --peer-addr 127.0.0.1:7000

The command prints one token to stdout. The token expires 15 minutes after mint. peren node join verifies the token against the same key directory, then writes an active membership record. Verification happens at join time, not on every peer request.

Rotation

Rotate Worker secret strings with Rotate secrets. Rotate provider env vars in the host environment or secret manager that supplies them, then restart or reload processes that read those names. Minted tokens expire; mint a new token when the previous one is past expires_at_ms.