RELIC_SERVICE_TOKEN environment variable is all you need.
How It Works
Each service account has its own RSA key pair. The project key is wrapped with the service account’s public key, and the private key is encrypted with a token-derived key using HKDF-SHA256. At runtime, the CLI derives the decryption key from the service token, decrypts the private key, unwraps the project key, and decrypts your secrets — all in a single HTTP call. The server never sees the raw token or any plaintext keys.Creating a Service Account
Service accounts are created through the CLI. You need to be the project owner and have a Pro plan.
The CLI will output a service token that is shown once. Store it immediately in your CI provider’s secret storage.
Using in CI/CD
SetRELIC_SERVICE_TOKEN in your pipeline environment, then run as usual:
RELIC_PASSWORD or RELIC_API_KEY needed. The service token handles both authentication and decryption.
GitHub Actions
GitLab CI
Managing Service Accounts
List
Revoke
Limits
- Maximum 5 active service accounts per project
- Maximum expiration of 365 days
- Expired and revoked accounts don’t count toward the limit
- Requires a Pro plan
Service Accounts vs API Keys
Using
RELIC_API_KEY with RELIC_PASSWORD in CI is deprecated. Migrate to service accounts for
better security and simpler configuration.OIDC Trust Policies
Service accounts can be hardened with OIDC trust policies, which verify the CI platform’s identity before allowing access. When configured, the service token only works when paired with a valid OIDC token from the trusted provider. See the OIDC Trust Policies guide for setup instructions.Key Rotation
When a project key is rotated (e.g. after revoking a collaborator’s share with rotation), active service accounts are automatically re-wrapped with the new key. No action is needed on your part — existing service tokens continue to work.Security Considerations
- Each service account is scoped to exactly one project
- The service token is shown once at creation time and cannot be retrieved later
- Service accounts can be revoked instantly from the CLI
- All service account usage is logged in the audit trail
- Projects with active service accounts cannot be archived — revoke them first
- The raw token never reaches the Relic server; only a SHA-256 hash is stored