How do I manage environment variables for a deployed app?

Updated October 2026 · How we answer

Short answerKeep secrets and environment-specific settings out of your code, set them in your hosting platform or a server env file with tight permissions, and restart the app after changes.

Keep config out of the code

Environment variables hold settings that change between environments, such as database URLs, API keys and feature flags. Keeping them out of source code lets the same build run in staging and production with different values. Commit a sample file such as .env.example with placeholder values, but never commit the real .env.

Most frameworks read variables from the process environment at startup. Restart the app after you change them, since running processes keep their old values.

  • Add .env to .gitignore
  • Commit .env.example with placeholders only
  • Set values in CI or hosting platform settings
  • Restart services after every change

Lock down the file on a server

If you keep a .env file on a Linux server, restrict it with chmod 600 .env so only its owner can read it. Make sure the owner is the user that runs the app. The deploy directory should also belong to that user or to a trusted deploy account.

Systemd services can load variables with EnvironmentFile= in the unit file. That keeps values out of the app folder and out of shell history. Some hosting platforms also let you mark variables as secret, which hides their values in the dashboard after you save them.

Common mistakes

  • Committing a real .env file to Git, even once, which leaves the secret in history.
  • Printing environment variables in logs during debugging.
  • Changing a variable and forgetting to restart the process.
From our shopsCASEONYX: Dark-luxe tough phone cases.