Run Docker Compose with encrypted environment variables
Keep your docker compose command. Wrap it with npx getmyenv run, or write the .env it reads with export. Includes Coolify.
Sep 28, 2026 · 4 min read
1. Set up the server
Set your Production values in the dashboard. In Project settings, Tokens, create a server token for Production with the server's IP. On the server:
bashexport GETMYENV_TOKEN=...
The first read from a new machine waits for your approval on Requests, unless the token trusts machines from its allowed IPs.
2. Compose that uses ${VAR}
Drop --env-file and wrap the same command. Values from run fill ${VAR} and bare environment: - VAR entries.
bashnpx getmyenv run production -- docker compose up -d
Docker keeps the values in the container config after up -d. Recreating the containers needs the command again.
3. Compose that reads a file
env_file: and a mounted .env need a real file. Add one line before your usual command:
bashnpx getmyenv export -c production -o ./.env --yes docker compose up -d
The file is plaintext, readable only by you on macOS and Linux, and stays on disk until you delete it. Keep it out of images with .dockerignore.
4. Coolify
Coolify's docker-compose.prod.yml reads /data/coolify/source/.env through env_file: and a bind mount. Put its values in a Production context, then write the file before you start or upgrade Coolify:
bashnpx getmyenv export -c production -o /data/coolify/source/.env --yes
Coolify reads the file while it runs, so it stays on disk. More on each path: /docs/docker.
Related docs: Docker and Compose, Machine access, CLI reference