# Is it possible to use deploy key for convox env?

**URL:** <https://community.convox.com/t/is-it-possible-to-use-deploy-key-for-convox-env/644>\
**Category:** CLI\
**Created:** [November 8, 2019, 10:24am UTC](https://community.convox.com/t/is-it-possible-to-use-deploy-key-for-convox-env/644 "2019-11-08T10:24:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![filip.golonka](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/filip.golonka/32/118_2.png) [@filip.golonka](https://community.convox.com/u/filip.golonka)\
**Post date:** [November 8, 2019, 10:24am UTC](https://community.convox.com/t/is-it-possible-to-use-deploy-key-for-convox-env/644/1 "2019-11-08T10:24:58Z")

</div>

Hey!

My usecase:

I’d like to keep both deploy logic and configuring the app (setting env variable) in the repo. CI system should build it, so first - set up env variables and then deploy the app. I don’t want to stick to my CONVOX\_API\_KEY, cause if I will die, the whole deployment will stop working. So I’d like to use deploy key. According to doc it works only for “convox build” and “convox deploy” and not for “convox env”. Correct? Or am I missing something?

---

<div class="post-metadata">

**Author:** ![ed\_convox](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/ed_convox/32/101_2.png) [@ed\_convox](https://community.convox.com/u/ed_convox)\
**Post date:** [November 8, 2019, 11:44am UTC](https://community.convox.com/t/is-it-possible-to-use-deploy-key-for-convox-env/644/2 "2019-11-08T11:44:17Z")

</div>

Hi Filip, I replied to your support ticket but will repeat here as well:  
It really isn’t good practice to store your env vars in your repo… Otherwise you may as well just hard-code them into your codebase! Env vars should be for the things that change between environment, and for secrets that you want to keep out of your repo. What’s your use case here?

---

<div class="post-metadata">

**Author:** ![filip.golonka](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/filip.golonka/32/118_2.png) [@filip.golonka](https://community.convox.com/u/filip.golonka)\
**Post date:** [November 8, 2019, 12:00pm UTC](https://community.convox.com/t/is-it-possible-to-use-deploy-key-for-convox-env/644/3 "2019-11-08T12:00:31Z")

</div>

Let’s continue here, maybe it will be useful for others as well 🙂

I am not going to store secrets in the repository. In my usecase Travis is responsible for building - all sensitive variables are available in the code, but encrypted. Then it is possible to just build again the app, because all the informations are available in the repository.

Travis doc regarding encrypting variables: [https://docs.travis-ci.com/user/encryption-keys/](https://docs.travis-ci.com/user/encryption-keys/)  
Usage: [https://docs.travis-ci.com/user/environment-variables/#defining-encrypted-variables-in-travisyml](https://docs.travis-ci.com/user/environment-variables/#defining-encrypted-variables-in-travisyml)

---

<div class="post-metadata">

**Author:** ![ed\_convox](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/ed_convox/32/101_2.png) [@ed\_convox](https://community.convox.com/u/ed_convox)\
**Post date:** [November 18, 2019, 10:00am UTC](https://community.convox.com/t/is-it-possible-to-use-deploy-key-for-convox-env/644/4 "2019-11-18T10:00:46Z")

</div>

Hey @filip.golonka,  
Thanks for that, it makes sense! I’ve made changes so this is now possible to do a `convox env set` and `convox env unset` with a deploy key and updated the docs to make it clear what else is possible: [https://docs.convox.com/console/deploy-keys](https://docs.convox.com/console/deploy-keys) 😄

Ed

---

<div class="post-metadata">

**Author:** ![filip.golonka](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/filip.golonka/32/118_2.png) [@filip.golonka](https://community.convox.com/u/filip.golonka)\
**Post date:** [November 18, 2019, 11:41am UTC](https://community.convox.com/t/is-it-possible-to-use-deploy-key-for-convox-env/644/5 "2019-11-18T11:41:52Z")

</div>

Thanks!
