A lightweight, free Payload CMS (MIT license) setup for Playwright API/UI testing.
A secret is a piece of sensitive information that your application needs to run — passwords, encryption keys, API tokens.
The golden rule is: never put secrets directly in your code or commit them to Git.
Why? Because code pushed to GitHub/GitLab is often visible to many people. If a secret is in a file like docker-compose.yml or server.ts, anyone who can read the code can see it. For a password this means their account is compromised. For an encryption key, all the data it protects is compromised.
Instead you store secrets in the environment — a separate place that exists only on the machine or service that needs it. Your code reads the value from that environment at runtime without ever containing the value itself.
This project uses three values that are treated as secrets/config:
| Variable | What it is | Sensitive? |
|---|---|---|
PAYLOAD_SECRET |
A long random string Payload uses to sign login tokens. Like a master key. | Yes — keep secret |
ADMIN_EMAIL |
The email address for the auto-created admin user | No |
ADMIN_PASSWORD |
The password for the auto-created admin user | Yes for production, fine as default for local dev |
- Docker Desktop (Linux engine running)
- Node.js 20+
The .env file is how you pass secrets to Docker Compose on your own machine. It is listed in .gitignore so it will never be committed to Git.
In the root of the project, copy the example file:
Windows (PowerShell):
Copy-Item .env.example .envMac / Linux:
cp .env.example .envOpen .env in VS Code and fill in real values:
PAYLOAD_SECRET=some-long-random-string-change-this
ADMIN_EMAIL=admin@example.com
ADMIN_PASSWORD=password
MONGODB_URI=mongodb://mongo:27017/payload
For PAYLOAD_SECRET, generate something random — any long string works locally, e.g. my-super-secret-dev-key-12345.
Never commit this file.
.gitignorealready excludes it, but double-check by runninggit status—.envshould not appear.
docker compose up -d --buildOn first run, the app automatically creates the admin user using the email/password from your .env.
Open the admin panel: http://localhost:3000/admin
Install Playwright browsers once:
npx playwright installRun all tests:
npm testOr by scope:
npm run test:api
npm run test:auth
npm run test:postsWhen tests run automatically on GitHub (on every push or pull request), the .env file is not available — it only exists on your local machine. Instead, you store secrets directly in GitHub so the pipeline can access them securely.
- Go to your repository on GitHub.
- Click Settings (top menu of the repo, not your account settings).
- In the left sidebar, click Secrets and variables → Actions.
- Click New repository secret.
- Name:
PAYLOAD_SECRET - Value: paste the same value you used in your
.envfile. - Click Add secret.
Secrets are encrypted by GitHub. Nobody can read them back — not even you — once saved. The pipeline can use them but they are masked in logs.
The pipeline defaults to admin@example.com / password. If you want different values:
- On the same Secrets and variables → Actions page, click the Variables tab.
- Click New repository variable.
- Add
ADMIN_EMAILand/orADMIN_PASSWORDas plain variables (not secrets, since they aren't sensitive for a dev environment).
Commit and push your code. GitHub will automatically run the Playwright tests on every push to main/master and every pull request.
To see results: go to your repository → Actions tab.
docker compose up -d # start in background
docker compose down # stop and remove containers
docker compose logs -f payload # follow live logsReset database (clears all data including the admin user):
docker compose down -vhttp://localhost:3000 Redirects to shop
http://localhost:3000/shop Product grid with category filter buttons
http://localhost:3000/shop?category=electronics Filtered product list
http://localhost:3000/shop/products/[](http://vscodecontentref/0) Product detail with Add to cart / Out of stock
http://localhost:3000/shop/orders Orders table with status badges
http://localhost:3000/admin CMS admin panel