Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Manage Goldsky secrets for pipeline sink credentials. Use when creating secrets for PostgreSQL, ClickHouse, Kafka, or other sinks, or when managing existing secrets.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | 162% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 119% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 151% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 73% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 174% | 0% |
Create and manage secrets for pipeline sink credentials.
Invoke this skill when the user:
/goldsky-secretsWhen this skill is invoked, follow this streamlined workflow:
Run goldsky secret list to confirm authentication and show existing secrets.
If authentication fails: Invoke the goldsky-auth-setup skill first.
Skip unnecessary questions. If the user's intent is clear from context, proceed directly:
Only use AskUserQuestion if intent is genuinely unclear.
If user provides a connection string, parse it directly instead of asking questions.
PostgreSQL connection string format:
postgres://USER:PASSWORD@HOST:PORT/DATABASE?sslmode=require
postgresql://USER:PASSWORD@HOST/DATABASEParsing logic:
user, password, host, port (default 5432), databaseNameExample - user provides:
postgresql://neondb_owner:abc123@ep-cool-name.us-east-2.aws.neon.tech/neondb?sslmode=requireCreate using the connection string directly:
bashgoldsky secret create --name SUGGESTED_NAME # When prompted, paste the connection string: # postgresql://neondb_owner:abc123@ep-cool-name.us-east-2.aws.neon.tech/neondb?sslmode=require
Neon:
postgresql://USER:PASS@ep-XXX.REGION.aws.neon.tech/neondbSupabase:
postgresql://postgres:PASS@db.PROJECT.supabase.co:5432/postgresPlanetScale (MySQL):
"protocol": "mysql" and port 3306Once you have credentials (from parsing or user input), create immediately:
bashgoldsky secret create \ --name SECRET_NAME \ --value '{"type":"jdbc","protocol":"postgres",...}' \ --description "Optional description"
Naming convention: PROJECT_PROVIDER (e.g., TRADEWATCH_NEON, ANALYTICS_SUPABASE)
Run goldsky secret list to confirm creation.
> JSON schema files are available in the schemas/ folder. Each file contains the full schema with examples.
| Secret Type | Schema File | Type Field | Use Case | | ------------- | -------------------- | --------------- | ------------------------------- | | PostgreSQL | postgres.json | jdbc | Database sink | | MySQL | postgres.json | jdbc | Database sink (protocol: mysql) | | ClickHouse | clickhouse.json | clickHouse | Analytics database | | Kafka | kafka.json | kafka | Event streaming | | AWS S3 | s3.json | s3 | Object storage | | ElasticSearch | elasticsearch.json | elasticSearch | Search engine | | DynamoDB | dynamodb.json | dynamodb | NoSQL database | | SQS | sqs.json | sqs | Message queue | | OpenSearch | opensearch.json | opensearch | Search/analytics | | Webhook | webhook.json | httpauth | HTTP endpoints |
Schema location: schemas/ (relative to this skill's directory)
PostgreSQL — Connection string format:
postgres://username:password@host:port/databasebashgoldsky secret create --name MY_POSTGRES_SECRET # The CLI will prompt for the connection string interactively
ClickHouse — Connection string format:
https://username:password@host:port/databaseKafka — JSON format:
json{ "type": "kafka", "bootstrapServers": "broker:9092", "securityProtocol": "SASL_SSL", "saslMechanism": "PLAIN", "saslJaasUsername": "user", "saslJaasPassword": "pass" }
S3 — Colon-separated format:
access_key_id:secret_access_keyOr with session token: access_key_id:secret_access_key:session_token
Webhook:
> Note: Turbo pipeline webhook sinks do not support Goldsky's native secrets management. Include auth headers directly in the pipeline YAML headers: field instead.
For PostgreSQL, use the helper script to parse connection strings:
bash./scripts/parse-connection-string.sh "postgresql://user:pass@host:5432/dbname" # Output: JSON ready for goldsky secret create --value
Show the user what will be created (mask password with \\\) and ask for confirmation before running the command.
Run goldsky secret list to confirm the secret was created.
| Action | Command | | ------ | --------------------------------------------------- | | Create | goldsky secret create --name NAME --value "value" | | List | goldsky secret list | | Reveal | goldsky secret reveal NAME | | Update | goldsky secret update NAME --value "new-value" | | Delete | goldsky secret delete NAME |
goldsky login)Pipelines that write to external sinks (PostgreSQL, ClickHouse, Kafka, S3) need credentials to connect. Instead of putting credentials directly in your pipeline YAML, you store them as secrets and reference them by name.
Benefits:
Before creating a secret, collect the connection details for your sink. The CLI requires specific JSON schemas for each type.
Interactive mode (recommended):
bashgoldsky secret create --name MY_SECRET
The CLI will prompt for the secret type and values interactively.
Non-interactive mode (for CI/CD or scripting):
All secrets require JSON format with a type field:
bashgoldsky secret create \ --name MY_POSTGRES_SECRET \ --value '{"type":"jdbc","protocol":"postgres","host":"db.example.com","port":5432,"databaseName":"mydb","user":"admin","password":"secret"}' \ --description "Production PostgreSQL database"
Expected output:
✔ Validated secret schema
✔ Created secretUse the secret name in your pipeline YAML:
PostgreSQL sink:
yamlsinks: postgres_output: type: postgres from: my_transform schema: public table: my_table secret_name: MY_POSTGRES_SECRET primary_key: id
ClickHouse sink:
yamlsinks: clickhouse_output: type: clickhouse from: my_transform table: my_table secret_name: MY_CLICKHOUSE_SECRET primary_key: id
bashgoldsky secret list
Expected output:
┌─────────────────────┬─────────────────────────────────┬─────────────────────┐
│ Name │ Description │ Created At │
├─────────────────────┼─────────────────────────────────┼─────────────────────┤
│ MY_POSTGRES_SECRET │ Production PostgreSQL database │ 2024-01-15 10:30:00 │
└─────────────────────┴─────────────────────────────────┴─────────────────────┘| Command | Purpose | Key Flags | | ------------------------------ | ------------------- | ------------------------------------ | | goldsky secret create | Create a new secret | --name, --value, --description | | goldsky secret list | List all secrets | | | goldsky secret reveal <name> | Show secret value | | | goldsky secret update <name> | Update secret value | --value, --description | | goldsky secret delete <name> | Delete a secret | -f (force, skip confirmation) |
bashgoldsky secret create --name PROD_POSTGRES # When prompted, provide the connection string: # postgres://admin:secret@db.example.com:5432/mydb
Pipeline usage:
yamlsinks: output: type: postgres from: my_source schema: public table: transfers secret_name: PROD_POSTGRES
bashgoldsky secret create --name CLICKHOUSE_ANALYTICS # When prompted, provide the connection string: # https://default:secret@abc123.clickhouse.cloud:8443/analytics
Pipeline usage:
yamlsinks: output: type: clickhouse from: my_source table: events secret_name: CLICKHOUSE_ANALYTICS primary_key: id
Update an existing secret without changing pipeline configs:
bashgoldsky secret update MY_POSTGRES_SECRET --value 'postgres://admin:NEW_PASSWORD@db.example.com:5432/mydb'
Active pipelines will pick up the new credentials on their next connection.
bash# With confirmation prompt goldsky secret delete OLD_SECRET # Skip confirmation (for scripts) goldsky secret delete OLD_SECRET -f
Warning: Deleting a secret that's in use will cause pipeline failures.
Use descriptive, uppercase names with underscores:
| Good | Bad | | -------------------- | ----------- | | PROD_POSTGRES_MAIN | secret1 | | STAGING_CLICKHOUSE | my-secret | | KAFKA_PROD_CLUSTER | postgres |
Include environment and purpose in the name for clarity.
Error: Secret 'MY_SECRET' not foundCause: The secret name doesn't exist or is misspelled. Fix: Run goldsky secret list to see available secrets and check the exact name.
Error: Secret 'MY_SECRET' already existsCause: Attempting to create a secret with a name that's already in use. Fix: Use goldsky secret update MY_SECRET --value "new-value" to update, or choose a different name.
Error: Invalid JSON in secret valueCause: JSON syntax error in the secret value. Fix: Validate your JSON before creating the secret:
bash# Test JSON validity echo '{"url":"...","user":"..."}' | jq .
Cause: The credentials in the secret are incorrect or the database is unreachable. Fix:
psql "postgresql://..."goldsky secret reveal MY_SECRETCause: Username or password in the secret is incorrect. Fix: Update the secret with correct credentials:
bashgoldsky secret update MY_SECRET --value 'postgres://correct:credentials@host:5432/db'
Cause: JSON strings with special characters need proper escaping. Fix: Use proper JSON escaping for special characters in password fields:
\\\"\nWith the structured JSON format, most special characters in passwords work without URL encoding since the password is a separate field.
Other measured skills in the registry, with their headline benchmark lift.