Environment variables

Keep configuration and secrets out of your code, with separate values for production and previews.

Add environment variables on the project's Environment variables tab, or with lahyer env set. Each variable has a value for production, for previews, or both, and the two can differ: previews can use a test API key while production uses the live one.

How values reach your app

  • During the build. Your build command sees the variables of the environment it builds for, so values your framework inlines at build time (NEXT_PUBLIC_, VITE_ and similar) reach the browser bundle. Anything inlined into browser code is public, so never give a secret one of those prefixes.
  • While it runs. Server apps read the variables from process.env.
  • Dockerfile apps get a variable during the image build only when the Dockerfile declares it with ARG; the running container gets all of them.

Changes apply to the next deployment. Running deployments keep the values they were built with, so the tab offers Redeploy after a change.

Keeping secrets secret

  • Values are encrypted at rest and lists never include them. Reveal one value at a time with the eye icon; every reveal is recorded in the audit log.
  • Values are masked in build logs.
  • Variables that Lahyer manages for you, such as your database connection string, are marked Set by your database and cannot be edited by hand.

Names and limits

  • Names use letters, digits and underscores, cannot start with a digit, and are up to 128 characters long.
  • Values are up to 32 KB, enough for certificates and JSON.
  • PORT, HOSTNAME, PATH, HOME, NODE_OPTIONS, CI and every name starting with LAHYER_ are reserved.
  • A project holds up to 100 variables on Free and 500 on Pro. A variable set for both production and previews counts twice.

Variables Lahyer sets

Every build and server process gets these:

NameValue
LAHYER1
LAHYER_ENVproduction or preview
LAHYER_URLThe address the deployment answers on
LAHYER_DEPLOYMENT_IDThe deployment's id
LAHYER_PROJECT_IDThe project's id
LAHYER_GIT_COMMIT_SHAThe commit being deployed
LAHYER_GIT_BRANCHIts branch
LAHYER_GIT_REPOSITORYThe repository's full name, such as acme/shop

Node.js server apps also get PORT, HOSTNAME and HOST (0.0.0.0) and NODE_ENV=production; Dockerfile apps get PORT. Production apps that list cron jobs get CRON_SECRET.

From the terminal

lahyer env ls                                     # names and targets, never values
lahyer env set API_KEY=abc123 --target production
lahyer env set --from-file .env.production --target production
lahyer env set API_KEY=def456 --overwrite         # replace an existing value
lahyer env rm OLD_TOKEN
lahyer env pull --target preview                  # writes .env.local

--target takes production, preview or all (the default; pull takes one environment and defaults to production). lahyer env pull writes a file only you can read: keep it out of git, and remember the reveal is recorded in the audit log.

On this page