Command Line Tools
wheels deploy secrets
Secret-store integration. Five built-in adapters (1Password, Bitwarden, AWS Secrets Manager, LastPass, Doppler), exposed behind three verbs.
The documented shell forms are the flat aliases wheels deploy fetch-secrets, wheels deploy extract-secrets, and wheels deploy print-secrets. Older CLI runtimes intercepted the nested wheels deploy secrets <verb> form in the top-level secrets command (#2697), which is why the flat aliases exist (#2699). On the current runtime the nested form also reaches deploy dispatch.
| Verb | Shell form | Purpose |
|---|---|---|
fetch | wheels deploy fetch-secrets | Pull keys from a named adapter. |
extract | wheels deploy extract-secrets | Extract one key from a KEY=VALUE block. |
print | wheels deploy print-secrets | Print the resolved .kamal/secrets. |
Adapter names
Section titled “Adapter names”Each adapter is registered under one or two aliases matching Kamal’s CLI conventions.
| Adapter | Aliases |
|---|---|
| 1Password | op, 1password |
| Bitwarden | bw, bitwarden |
| AWS Secrets Manager | aws |
| LastPass | lpass, lastpass |
| Doppler | doppler |
Adapters shell out to the corresponding CLI tool on the control machine. See Secrets for setup.