Environment (kind: environment)
Real declared variables, secrets, and feature flags — what ${var:KEY}/${secret:KEY}/
${feature:KEY} tokens (used throughout network/firewall/
dns/module documents) resolve against.
A deliberately small slice of v1’s environment model: a census of 26 real environment documents
across two production repos found overrides/lifecycle/promotion at zero real usage, so none
of that machinery is ported.
Schema
spec.variables[]/spec.secrets[]/spec.features[]— each entry:{key, store, value, version, description}Variable
storevalues:constant,environment,artifact,azure-appconfig,flagsmithSecret
storevalues:constant,environment,github,azure-keyvault,bitwarden,vault,infisicalFeature
storevalues:constant,environment,azure-appconfig,flagsmithOnly
constant/environment/github/artifactresolve to anything today (see Notes) — the rest validate as recognized names, naming a capability-backedintegration, but have no runtime resolver wired up yetvalue— the store’s own addressing scheme: a literal (constant), an environment variable name (environment/github), or a secret path/ID/flag key for an integration-backed storeSecrets additionally support
generate: {type, length}(auto-generate when the key is missing) androtate(age-based or automatic rotation policy) — integration-backed stores only
spec.properties— merged as a layer into every deployment using this environment (tenant properties merge first, then this, then the deployment’s own)spec.custom— free-form data for scripts/extensions
Example
apiVersion: strata.huybrechts.xyz/v2
kind: environment
meta:
name: prd
annotations:
description: "Example production environment"
spec:
properties:
deploy_tier: production
variables:
- key: PUBLIC_IP
store: constant
value: "203.0.113.10"
- key: REGION
store: constant
value: westeurope
secrets:
- key: DB_PASSWORD
store: environment
value: EXAMPLE_DB_PASSWORD
description: "Read from the EXAMPLE_DB_PASSWORD environment variable"
Notes
Keys are unique per store, not globally —
${var:X}and${secret:X}are different tokens, so the same key name in both a variable and a secret is legitimate.Only
constant/environment/github/artifactstores resolve to anything today — any otherstorevalue validates as a recognized name but has no runtime resolver behind it yet, same discipline asprovisioner’s opentoolfield.Inspect what a deployment actually resolves with
strata values get DEPLOYMENT KEY...before building or deploying — see docs/README.md.