How do I manage environment variables for a deployed app?
Keep config out of the code
Environment variables hold settings that change between environments, such as database URLs, API keys and feature flags. Keeping them out of source code lets the same build run in staging and production with different values. Commit a sample file such as .env.example with placeholder values, but never commit the real .env.
Most frameworks read variables from the process environment at startup. Restart the app after you change them, since running processes keep their old values.
- Add .env to .gitignore
- Commit .env.example with placeholders only
- Set values in CI or hosting platform settings
- Restart services after every change
Lock down the file on a server
If you keep a .env file on a Linux server, restrict it with chmod 600 .env so only its owner can read it. Make sure the owner is the user that runs the app. The deploy directory should also belong to that user or to a trusted deploy account.
Systemd services can load variables with EnvironmentFile= in the unit file. That keeps values out of the app folder and out of shell history. Some hosting platforms also let you mark variables as secret, which hides their values in the dashboard after you save them.
Common mistakes
- Committing a real .env file to Git, even once, which leaves the secret in history.
- Printing environment variables in logs during debugging.
- Changing a variable and forgetting to restart the process.
