Skip to content

Run Docker Compose with encrypted environment variables

Keep your docker compose command. Wrap it with npx getmyenv run, or write the .env it reads with export. Includes Coolify.

Sep 28, 2026 · 4 min read

1. Set up the server

Set your Production values in the dashboard. In Project settings, Tokens, create a server token for Production with the server's IP. On the server:

bash
export GETMYENV_TOKEN=...

The first read from a new machine waits for your approval on Requests, unless the token trusts machines from its allowed IPs.

2. Compose that uses ${VAR}

Drop --env-file and wrap the same command. Values from run fill ${VAR} and bare environment: - VAR entries.

bash
npx getmyenv run production -- docker compose up -d

Docker keeps the values in the container config after up -d. Recreating the containers needs the command again.

3. Compose that reads a file

env_file: and a mounted .env need a real file. Add one line before your usual command:

bash
npx getmyenv export -c production -o ./.env --yes docker compose up -d

The file is plaintext, readable only by you on macOS and Linux, and stays on disk until you delete it. Keep it out of images with .dockerignore.

4. Coolify

Coolify's docker-compose.prod.yml reads /data/coolify/source/.env through env_file: and a bind mount. Put its values in a Production context, then write the file before you start or upgrade Coolify:

bash
npx getmyenv export -c production -o /data/coolify/source/.env --yes

Coolify reads the file while it runs, so it stays on disk. More on each path: /docs/docker.

Related docs: Docker and Compose, Machine access, CLI reference