# Monorepo access token setup tedious

**URL:** <https://community.doppler.com/t/monorepo-access-token-setup-tedious/599>\
**Category:** Feature Requests\
**Created:** [April 16, 2022, 12:47pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599 "2022-04-16T12:47:13Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![blunick](https://avatars.discourse-cdn.com/v4/letter/b/ea666f/32.png) [@blunick](https://community.doppler.com/u/blunick)\
**Post date:** [April 16, 2022, 12:47pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/1 "2022-04-16T12:47:14Z")

</div>

Regarding service tokens:

I understand the principle of least privilege, scoping everything per project and config.

But when using a Monorepo and something like [Turborepo](https://turborepo.org/) or [NX](https://nx.dev/), the access token setup and control can become very tedious for the CI/CD pipeline. For CI I would need one access token that has access to all `CI` or `TEST` configs, instead of 10+ tokens, when running many services.

Is there a way to share a token between configs, so it would have access to multiple projects+configs?

**EDIT:**  
Ok, it seems the token (alone) clearly identifies environment + config, and only the token is needed to let Doppler CLI know, what secrets to get, which kind of contradicts the suggestion above.  
Still, some best practices for Monorepos would be great in the docs.

By the way: This is one of the best and most useful services I have used in the last years. The dashboard UI is also superb!

---

<div class="post-metadata">

**Author:** ![ryan-blunden](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/ryan-blunden/32/9_2.png) [@ryan-blunden](https://community.doppler.com/u/ryan-blunden)\
**Post date:** [April 20, 2022, 5:36am UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/2 "2022-04-20T05:36:03Z")

</div>

Hey @blunick and welcome to the Doppler community.

Glad you got this figured out and we’ll get some monorepo docs added soon.

Out of interest, what CI/CD environment are you using?

---

<div class="post-metadata">

**Author:** ![blunick](https://avatars.discourse-cdn.com/v4/letter/b/ea666f/32.png) [@blunick](https://community.doppler.com/u/blunick)\
**Post date:** [April 20, 2022, 6:31am UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/3 "2022-04-20T06:31:42Z")

</div>

Hey @ryan-blunden , that’s great.

We use [https://semaphoreci.com/](https://semaphoreci.com/) cause they run on quite fast machines.

---

<div class="post-metadata">

**Author:** ![ryan-blunden](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/ryan-blunden/32/9_2.png) [@ryan-blunden](https://community.doppler.com/u/ryan-blunden)\
**Post date:** [April 20, 2022, 7:59am UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/4 "2022-04-20T07:59:41Z")

</div>

Nice! I hadn’t heard of them. Will check them out.

Thanks!

---

<div class="post-metadata">

**Author:** ![sambs](https://avatars.discourse-cdn.com/v4/letter/s/dfb087/32.png) [@sambs](https://community.doppler.com/u/sambs)\
**Post date:** [November 23, 2022, 7:26am UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/5 "2022-11-23T07:26:02Z")

</div>

I’m also wondering how to go about configuring tokens for CI. I need to be able to access ~ 8 projects and 3 environments per project which means adding 24 different doppler tokens as secrets!

---

<div class="post-metadata">

**Author:** ![watsonian](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/watsonian/32/267_2.png) [@watsonian](https://community.doppler.com/u/watsonian)\
**Post date:** [January 20, 2023, 7:27pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/7 "2023-01-20T19:27:56Z")

</div>

Hi @sambs!

We actually are working on a new feature called Service Accounts that should help a lot in this respect. It will let you generate tokens that have access to multiple projects and configs by creating a “service account” that you can add to projects and configs like normal users to control what they have access to. This feature should be out in the relatively near future, so keep an eye out for it!

Regards,  
-Joel

---

<div class="post-metadata">

**Author:** ![sambs](https://avatars.discourse-cdn.com/v4/letter/s/dfb087/32.png) [@sambs](https://community.doppler.com/u/sambs)\
**Post date:** [January 25, 2023, 9:26am UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/8 "2023-01-25T09:26:19Z")

</div>

Great news @watsonian, that’s exactly what we need!

---

<div class="post-metadata">

**Author:** ![Grraahaam](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/grraahaam/32/661_2.png) [@Grraahaam](https://community.doppler.com/u/Grraahaam)\
**Post date:** [January 25, 2023, 3:51pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/9 "2023-01-25T15:51:09Z")

</div>

Hey @watsonian ! Do you have further details on this feature?

I’d like to know if it’d be possible to use it within github actions (as the OP is asking), like the following (e.g. with `DOPPLER_TOKEN_MY_APP` a “service account” token having access to three projects) :

```yaml
name: Example action

on: [push]

jobs:
  my-job:
    runs-on: ubuntu-latest
    steps:
      - name: Install CLI
        uses: dopplerhq/cli-action@v2
      - name: Do something with the CLI
        run: doppler secrets --only-names
        env:
          DOPPLER_TOKEN: ${{ secrets.DOPPLER_TOKEN_MY_APP }}

```

Since I find the Github integration for an entire organization a bit difficult to use and not easily scalable (every repository need to be added one by one), it’d be easier for us to workaround it by implementing the `dopplerhq/cli-action` (above example) as a composite/global action ([Composite actions](https://docs.github.com/en/actions/creating-actions/creating-a-composite-action) + [Organization required workflows](https://github.blog/changelog/2023-01-10-github-actions-support-for-organization-wide-required-workflows-public-beta/)) with a token that can fetch multiple projects at once. Let me know if there’s a better way to achieve this ✌

Cheers!

---

<div class="post-metadata">

**Author:** ![Grraahaam](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/grraahaam/32/661_2.png) [@Grraahaam](https://community.doppler.com/u/Grraahaam)\
**Post date:** [January 25, 2023, 3:52pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/10 "2023-01-25T15:52:12Z")

</div>

PS: I also have an open issue **[#359](https://github.com/DopplerHQ/cli/issues/359)** about a similar feature, I’m wondering if the “service account” feature will provide the same possibilities? 🤔

---

<div class="post-metadata">

**Author:** ![watsonian](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/watsonian/32/267_2.png) [@watsonian](https://community.doppler.com/u/watsonian)\
**Post date:** [January 25, 2023, 5:02pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/11 "2023-01-25T17:02:06Z")

</div>

Hi @Grraahaam!

Yep, it would definitely be possible to use one of these service account tokens in our GitHub Action. All that action does is install our CLI. You then just pass in the `DOPPLER_TOKEN` environment variable with a valid token (which could be a service account token) and then you can execute CLI commands. Note that you’d need to specify the project and config in those commands since it can no longer be inferred from the token itself. We do also have this action available as well:

> **[Fetch Doppler Secrets - GitHub Marketplace](https://github.com/marketplace/actions/fetch-doppler-secrets)**
>
> Fetch Doppler secrets for a specific Project and Config

> [@Grraahaam](#):
>
> Since I find the Github integration for an entire organization a bit difficult to use and not easily scalable (every repository need to be added one by one)

Yeah, I can see how that could be easier to setup for sure. One thing to consider is that syncing secrets to GitHub does provide you an amount of insulation from outages or other issues. For example, if there were ephemeral network connectivity issues on GitHub’s side for outbound connections, it wouldn’t impact you if you were reading synced secrets most likely whereas it would if you were making API calls to Doppler for every workflow execution. Inversely, if we had some sort of outage, your actions would all fail until that was fixed. If you were using syncs, then your builds would continue working fine. Just something to consider!

Also, regarding the open issue you have – these service account tokens should solve what you’re after there!

---

<div class="post-metadata">

**Author:** ![Grraahaam](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/grraahaam/32/661_2.png) [@Grraahaam](https://community.doppler.com/u/Grraahaam)\
**Post date:** [January 26, 2023, 9:49am UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/12 "2023-01-26T09:49:45Z")

</div>

Thanks for the insights!

I do understand the “sync” benefits over the “github action” ones, and I’d rather use the “sync” option myself! But until you support Github organization secrets syncs, we need to find a scalable/automated workaround to automatically inject secrets into our newly created repos’ workflows (since we’re a small team, having it done automatically would be awesome)

It seems possible to sync Github organization secrets through their API tho, and you could even automatically import existing Github secrets to a Doppler project as well (they have a LIST/GET endpoint). But there may be some security concerns behind, which I’m not aware of yet. Anyway here’s the mentioned API if ever you guys plan to support it (I’d love it) :

- [GH Secrets - List Organization Secrets](https://docs.github.com/en/rest/actions/secrets?apiVersion=2022-11-28#list-repository-secrets)
- [GH Secrets - Create/Update Organization Secrets](https://docs.github.com/en/rest/actions/secrets?apiVersion=2022-11-28#create-or-update-an-organization-secret)

* * *

Do you know if it’d be possible to automatically generate service accounts tokens from a config file with `doppler setup`, like with the `doppler.yaml` today, or the feature is still in an early stage and the communication is planned for later?

Thanks! ✌

---

<div class="post-metadata">

**Author:** ![sambs](https://avatars.discourse-cdn.com/v4/letter/s/dfb087/32.png) [@sambs](https://community.doppler.com/u/sambs)\
**Post date:** [March 1, 2023, 4:24pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/13 "2023-03-01T16:24:31Z")

</div>

Any update on Service Account availability @watsonian?

---

<div class="post-metadata">

**Author:** ![siggy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/siggy/32/721_2.png) [@siggy](https://community.doppler.com/u/siggy)\
**Post date:** [March 17, 2023, 6:53pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/14 "2023-03-17T18:53:18Z")

</div>

Ping - any update?

We are now at the stage where we use personal access token to get secrets.  
This is the opposite to secure, but it’s currently the only option unless we split our monorepo (which makes no sense)

---

<div class="post-metadata">

**Author:** ![watsonian](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/watsonian/32/267_2.png) [@watsonian](https://community.doppler.com/u/watsonian)\
**Post date:** [March 20, 2023, 6:25pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/15 "2023-03-20T18:25:26Z")

</div>

@sambs @siggy Our Service Accounts feature is getting close! Baring any major issues, I believe we’re planning on getting it out this quarter still.

@Grraahaam I don’t believe it will be possible to generate service account tokens from a config file like you’re describing.

As an aside, people on this thread might be interested in this CLI change that will be going out in the very near future:

> <https://github.com/DopplerHQ/cli/pull/374>
>
> This adds support for a more monorepo-friendly setup file. Historically, a setup… file (\`doppler.yaml\`) had this format:
> 
> \`\`\`
> setup:
> project: cli
> config: dev
> \`\`\`
> 
> It could only contain values for a single project+config combination. If you had a monorepo that contained many services as subdirectories, you had to essentially add one of these to each of the subdirectories and then have a script go through running \`doppler setup\` in each directory (or clever usage of \`find\` on linux systems).
> 
> This change now supports setup files in this format:
> 
> \`\`\`
> setup:
> - project: cli
> config: dev
> path: .
> - project: example
> config: stg
> path: example/
> \`\`\`
> 
> It lets you specify multiple project+repo combinations and adds a new \`path\` field. If no \`path\` field is specified, then it refers to the root directory. If one is specified, it's relative to the root directory.
> 
> The change maintains backwards compatibility with old setup files while allowing the new usage. If the new format is detected, it will loop through, prompting you if you want to perform the setup for each directory (and prints the directory it's performing the setup for). \`--no-interactive\` will work as expected in this case. If the old format is detected, then everything works as it has historically.
> 
> Fixes ENG-3644.

---

<div class="post-metadata">

**Author:** ![watsonian](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/watsonian/32/267_2.png) [@watsonian](https://community.doppler.com/u/watsonian)\
**Post date:** [April 20, 2023, 9:50pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/19 "2023-04-20T21:50:18Z")

</div>

Monorepo setup files are now supported in v3.57.0 of the CLI! So, if you update you can start taking advantage of this now!

---

<div class="post-metadata">

**Author:** ![watsonian](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/watsonian/32/267_2.png) [@watsonian](https://community.doppler.com/u/watsonian)\
**Post date:** [April 21, 2023, 4:12pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/20 "2023-04-21T16:12:58Z")

</div>

Unfortunately, we’re having to roll this change back due to some issues it caused that we didn’t catch initially (notably, it broke interactive invocations of `doppler setup`). We had a tentative fix ready for it, but decided to rollback instead so we had more time to review things. I’ll post again here when the fixed version is released with support for this.

---

<div class="post-metadata">

**Author:** ![watsonian](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/watsonian/32/267_2.png) [@watsonian](https://community.doppler.com/u/watsonian)\
**Post date:** [August 27, 2024, 3:02pm UTC](https://community.doppler.com/t/monorepo-access-token-setup-tedious/599/21 "2024-08-27T15:02:01Z")

</div>

Just as a follow up here, [Service Accounts](https://docs.doppler.com/docs/service-accounts) have been released for some time now (it requires the Team plan though), which should solve for the need to use Personal Access Tokens for monorepo setups (instead, create a Service Account that has read access to secrets on the configs required for the services in the monorepo). The monorepo setup file support for the CLI has as well, so that should make CLI setup easier as well!
