Environment variables
Keep configuration and secrets out of your code, with separate values for production and previews.
Add environment variables on the project's Environment variables tab, or with lahyer env set. Each variable has a value for production, for previews, or both, and the two can differ: previews can use a test API key while production uses the live one.
How values reach your app
- During the build. Your build command sees the variables of the environment it builds for, so values your framework inlines at build time (
NEXT_PUBLIC_,VITE_and similar) reach the browser bundle. Anything inlined into browser code is public, so never give a secret one of those prefixes. - While it runs. Server apps read the variables from
process.env. - Dockerfile apps get a variable during the image build only when the Dockerfile declares it with
ARG; the running container gets all of them.
Changes apply to the next deployment. Running deployments keep the values they were built with, so the tab offers Redeploy after a change.
Keeping secrets secret
- Values are encrypted at rest and lists never include them. Reveal one value at a time with the eye icon; every reveal is recorded in the audit log.
- Values are masked in build logs.
- Variables that Lahyer manages for you, such as your database connection string, are marked Set by your database and cannot be edited by hand.
Names and limits
- Names use letters, digits and underscores, cannot start with a digit, and are up to 128 characters long.
- Values are up to 32 KB, enough for certificates and JSON.
PORT,HOSTNAME,PATH,HOME,NODE_OPTIONS,CIand every name starting withLAHYER_are reserved.- A project holds up to 100 variables on Free and 500 on Pro. A variable set for both production and previews counts twice.
Variables Lahyer sets
Every build and server process gets these:
| Name | Value |
|---|---|
LAHYER | 1 |
LAHYER_ENV | production or preview |
LAHYER_URL | The address the deployment answers on |
LAHYER_DEPLOYMENT_ID | The deployment's id |
LAHYER_PROJECT_ID | The project's id |
LAHYER_GIT_COMMIT_SHA | The commit being deployed |
LAHYER_GIT_BRANCH | Its branch |
LAHYER_GIT_REPOSITORY | The repository's full name, such as acme/shop |
Node.js server apps also get PORT, HOSTNAME and HOST (0.0.0.0) and NODE_ENV=production; Dockerfile apps get PORT. Production apps that list cron jobs get CRON_SECRET.
From the terminal
lahyer env ls # names and targets, never values
lahyer env set API_KEY=abc123 --target production
lahyer env set --from-file .env.production --target production
lahyer env set API_KEY=def456 --overwrite # replace an existing value
lahyer env rm OLD_TOKEN
lahyer env pull --target preview # writes .env.local--target takes production, preview or all (the default; pull takes one environment and defaults to production). lahyer env pull writes a file only you can read: keep it out of git, and remember the reveal is recorded in the audit log.