Skip to main content
Relic works in CI/CD environments using service accounts (recommended) or API keys. Service accounts require only a single environment variable and don’t need your master password. Service accounts provide passwordless CI/CD integration. See the Service Accounts guide for full details.
1

Create a service account

For GitHub Actions with OIDC (recommended):
The CLI outputs a service token. Store it in your CI provider’s secret storage.
2

Set the environment variable

3

Run with secrets

GitHub Actions

The id-token: write permission is required if you configured OIDC on your service account. Without OIDC, it can be omitted.

GitLab CI

Other Providers

Relic works with any CI/CD provider that supports environment variables. The pattern is always the same:
  1. Install Relic (bun add -g relic or npm install -g relic)
  2. Set RELIC_SERVICE_TOKEN in your pipeline environment
  3. Run relic run -e <environment> -- <your command>

OIDC Trust Policies

For additional security, add OIDC trust policies to your service accounts. This verifies the CI platform’s identity so the service token only works from trusted environments. See the OIDC Trust Policies guide for details.

API Keys (Legacy)

Using RELIC_API_KEY with RELIC_PASSWORD in CI is deprecated. Migrate to service accounts for better security and simpler setup.
API keys still work but require two environment variables (RELIC_API_KEY + RELIC_PASSWORD) and expose your master password to the CI environment. To use API keys:

Scope Filtering

Use --scope to inject only a subset of secrets:
This is useful when your build step only needs client-side variables and shouldn’t have access to server secrets.

Folder Filtering

Use --folder to inject secrets from a specific folder:
Useful in monorepos where different services need different secrets from the same environment.

Security Considerations

Store RELIC_API_KEY and RELIC_PASSWORD in your CI provider’s secret storage. Never hardcode them in pipeline files or commit them to your repository.
  • API keys can be revoked from the web dashboard at any time
  • Each API key has scoped permissions (secrets.read, user.keys.read)
  • API keys can be scoped to a specific project, restricting access to only that project’s secrets
  • All API keys require an expiration date (maximum 365 days)
  • API key usage is logged in the audit trail
  • The master password is used only for decryption and is never sent to the Relic server
Last modified on May 2, 2026