> ## Documentation Index
> Fetch the complete documentation index at: https://docs.phala.com/llms.txt
> Use this file to discover all available pages before exploring further.

# envs

> Encrypt and update CVM sealed environment variables

### Command: `phala envs`

#### Syntax

```
phala envs <command> [options]
```

#### Description

Encrypt and update CVM sealed environment variables

#### Global Options

| Option                               | Description                                                  |
| ------------------------------------ | ------------------------------------------------------------ |
| `-h, --help`                         | Show help information for the current command                |
| `-v, --version`                      | Show CLI version                                             |
| `--api-token TOKEN, --api-key TOKEN` | API token for authenticating with Phala Cloud                |
| `-j, --json, --no-json`              | Output in JSON format                                        |
| `--interactive`                      | Enable interactive mode for commands that support it         |
| `--cvm-id <value>`                   | CVM identifier (UUID, app\_id, instance\_id, or name)        |
| `--profile PROFILE`                  | Temporarily use a different auth profile for this command    |
| `--api-version <value>`              | API version to use (e.g. 2026-01-21, 2026-05-22, 2026-06-23) |
| `--timeout SECONDS`                  | Request timeout in seconds (default 60)                      |

#### Examples

* Display help:

```bash theme={"system"}
phala envs --help
```

### Subcommands

| Command   | Description                                                                       |
| --------- | --------------------------------------------------------------------------------- |
| `encrypt` | Encrypt environment variables for a CVM (sealed, only readable inside TEE)        |
| `update`  | Encrypt and push sealed environment variables to a CVM (only readable inside TEE) |
