Learning on Web Dev Open is free for all.

Backend Engineering > Proving it works, then shipping itEnvironments, and the secret you nearly committed
Phase 05Proving it works, then shipping it276 of 434

Environments, and the secret you nearly committed

Development, preview and production as three real configurations, with secrets that live in the platform and never in the repository.

Concept13 minAI pair

Three environments, three complete sets of configuration. Development points at a local or throwaway database. Preview gets its own, seeded, and never the production one: a preview deploy is code nobody has reviewed yet, connected to whatever you point it at. Production is the only one with real user data, and access to its variables should be narrower than access to the code.

Secrets belong in the platform's encrypted store, injected at runtime as environment variables. Keep a committed .env.example with every key name and no values, so a new contributor knows what to ask for and a missing variable fails at boot with a clear message rather than at midnight with a null. Validate the environment at startup: a schema over process.env costs ten lines and turns a class of runtime mystery into a refusal to start.

Practise a rotation before you need one. Pick a non-critical key, rotate it, and see what breaks and how long it takes. The first rotation you ever do should not be the one at two in the morning after a leak.

You should now be able to

  • Separate configuration per environment
  • Store secrets where they belong and rotate one
  • Explain what a preview deployment should point at
Ask the community

Loading…