🚀 The Simple Version
Think of environment variables like the ingredients in a secret recipe. The code (the recipe) is public, but the exact amounts (the variables) stay private.
1. What Are They?
Environment variables are key‑value pairs that your program reads at runtime. They store things like API keys, database URLs, or feature flags.
2. How to Use Them
Most languages provide a simple way to access them. For example, in Node.js you can write:
const apiKey = process.env.API_KEY;
In Python:
import os
api_key = os.getenv("API_KEY")
3. Why You Should Never Commit a .env File
Committing a .env file is like posting the secret recipe on a public forum. Anyone who can see your repo can also see your passwords and tokens. If your code is open or shared on GitHub, those secrets could be stolen.
4. Keeping Secrets Safe
- Add the file to
.gitignoreso Git never tracks it. - Use a tool like
dotenvlocally, but load secrets from a secure store (e.g., AWS Secrets Manager, GitHub Actions secrets) in production. - Rotate keys regularly so even if a leak happens, the window of damage is small.
5. Quick Checklist
- Do you have a
.envfile? Yes → add it to.gitignore. - Are you printing environment variables in logs? No → remove any debug prints.
- Do your CI/CD pipelines load secrets from a secure vault? Yes → great!