Secrets reach running Jobs, Sandboxes and Workspaces
A Job, Sandbox or Workspace that names a Secret under secrets or env[].valueFrom.secretKeyRef now receives
it: every key of a listed Secret as an env var and a read-only file /run/secrets/<secret>/<key>, and each
secretKeyRef under the name you chose. A Job receives the Secret versions pinned when you submitted it, even if
you write a new value while it runs; a Sandbox pins the newest version each time it starts.
Sandboxes accept secrets and valueFrom.secretKeyRef.
Private images named with imagePullSecrets are pulled with that Registry Secret on the machine that runs the
work. The credential is used for the pull alone and never appears in the container.
A command started with nodus exec or the Processes API whose env contains the value of one of the project’s
Secrets is refused with SecretValueInEnv; reference the Secret instead. Values shorter than 8 characters are not
checked, and an env that sets a name twice is refused.
An attempt whose Secret was deleted (or deleted and recreated under the same name), or whose pinned version was
replaced before the attempt started, fails with LaunchFailed instead of waiting to start.
Secrets delivered as env vars may total at most 1 MiB per container, and as files at most 8 MiB.