Skip to content

Secrets and Environment Variables

Stable Build Reviewed 2026-09-27 purview-dev/build build-pipeline cd ci composite-action csharp devops dogfooding dotnet github-actions modular-pipelines nuget reusable-workflow

Secrets must never be committed. They are supplied at runtime via environment variables / CI secrets and read by the pipeline through the settings’ lookup helpers.

Command line > environment variables > purview-build.json > baked-in defaults. Nested environment keys use __, for example Release__Mode=NuGet. Because env vars take precedence over purview-build.json, an empty forwarded env var can silently override a configured value — the reusable workflows only forward optional test settings when the caller actually provides them.

SecretWhere it is usedEnvironment-var bound alias
NUGET_APIKEYNuGet pushNuGet__NUGET_APIKEY (binds EnvAPIKey); also read directly from process env NUGET_APIKEY/NUGET_API_KEY
NuGet__ApiKeyNuGet pushAPIKey
GITHUB_TOKENGitHub release creationGitHub__GITHUB_TOKEN (binds EnvAccessToken); also read directly from process env GITHUB_TOKEN
LOCAL_NUGET_FEED_PATHLocal NuGet publishingPublishLocalNuGet__LOCAL_NUGET_FEED_PATH (binds EnvLocalFeedPath); also read directly from process env LOCAL_NUGET_FEED_PATH

The config binder does not map plain NUGET_APIKEY/GITHUB_TOKEN/LOCAL_NUGET_FEED_PATH process env vars under their settings sections, so the settings classes fall back to reading the process environment directly.

The reusable workflows (purview-build.yml, purview-release.yml) forward the caller’s test-filter and test-projects inputs as Build__TestFilter/Build__TestProjects only when they are non-empty. An empty forwarded value would override a consuming repository’s purview-build.json (env vars take precedence over JSON) and silently disable the filter — see commit 4d72bf7.

VariablePurpose
PURVIEW_BUILD_STACKTRACESet to 1 (or true) to include stack traces in failure reports. Unset, a failing run prints only the failing module and that module’s output, then exits with code 1.

Pipeline verbosity is configured with Build__LogLevel (default Information, which reports each module’s command output and progress); set Build__LogLevel=Warning for quiet CI logs.