capy deploy. It emits SECRETS_BLOB and PROJECT_KEY. Put both in the container environment and make capy run the entrypoint.
Install Capy in the image
The npm package is the simplest choice for a Node application:.env, .env.pre-capy.old, and local Capy state from the image with .dockerignore.
Build the image without the runtime pair. Supply it when the container starts:
/etc/my-app/capy-runtime.env should contain only deployment configuration and be readable by the account that starts the container:
Compose and Kubernetes
Keep the pair outside the application repository. For Compose, point at an externally managed env file:.env in deployed mode. With the emitted SECRETS_BLOB / PROJECT_KEY names, any same-named variable already present in the container takes precedence; remove stale plaintext duplicates when the Capy value must be used.
Updates and revocation
Create a distinct pair for each environment. When values change, mint a new pair from the correct Capy branch, update the external secret store, and restart the workload. Revoke unused pairs withcapy deploy revoke <deploy-id>; already-running containers retain their environment until they restart.
Running your app
Runtime-pair mode detection and precedence.