Environment Variables & Secrets
Configure application-specific values without hardcoding them into source code.
1. What Are Environment Variables?
Environment variables allow you to configure sensitive values, credentials, and environment-specific parameters outside your source code. Common examples include:
- Database connection strings (
DATABASE_URL) - Third-party API keys (Stripe, OpenAI, SendGrid)
- Authentication secrets (
NEXTAUTH_SECRET,JWT_SECRET) - Feature flags and base API endpoints
2. Adding an Environment Variable
To add an environment variable to your project:
- Open your project and go to Project Settings → Environment Variables.
- Enter the Key (e.g.
DATABASE_URL). Keys should use uppercase letters and underscores. - Enter the Value (e.g.
postgres://user:pass@host:5432/db). - Select the target environment scope (Production, Preview, or Both).
- Click Save Variable.
3. Production vs. Preview Scoping
Aureon enables environment scoping so your test builds never touch production databases:
- Production: Injected only into deployments on your primary production branch.
- Preview: Injected into pull requests and feature branch preview deployments.
4. Updating Variables & Required Redeployment
When you update or add an environment variable, running application containers do not update automatically. You must trigger a new deployment for the updated variables to be injected into the build and container environment.
5. Protecting Secrets: Security Rules
- Never commit
.envfiles: Add.envand.env.localto your.gitignorefile before committing. - Client-Side Exposure: Remember that variables prefixed with
NEXT_PUBLIC_orVITE_are embedded into the client JavaScript bundle and are visible to anyone in their browser. Never place secret API keys or private database passwords into client-prefixed variables.
6. Common Environment Variable Mistakes
- Casing mistakes: Environment variable keys are strictly case-sensitive.
API_KEYis different fromApi_Key. - Unquoted special characters: If a variable value contains quotes or symbols, ensure there is no leading or trailing whitespace.
- Missing rebuild: Forgetting to trigger a new deployment after saving the variable in the dashboard.