Docs · Configuration

Environment variables: config without commits.

Environment variables are named values, like DATABASE_URL or STRIPE_SECRET_KEY, that Runex injects into your app at runtime. Set them in the dashboard so secrets never live in your Git history.

  • Set in the dashboard
  • Separate preview values
  • Redeploy to apply
acme/api · env
DATABASE_URL
postgres://… · managed
STRIPE_SECRET_KEY
•••••••• · secret
NEXT_PUBLIC_API_URL
https://api.acme.com
NODE_ENV
production
illustrative valuesrunex

Definition

What is an environment variable?

A key-value setting the operating system passes to your process when it starts.

Your code reads it by name: process.env.DATABASE_URL in Node.js, os.environ["DATABASE_URL"] in Python, os.Getenv("DATABASE_URL") in Go.

Keeping configuration in environment variables means the same code runs in previews and production with different values, and secrets stay out of the repository.

How to

How do you set environment variables on Runex?

Add them in the dashboard, then redeploy.

  1. Open your app in the Runex dashboard and go to Environment variables.
  2. Add a name and value, such as API_KEY.
  3. Choose where it applies: production, previews, or both.
  4. Redeploy so the running app picks up the new value.

Compare

Build-time vs runtime variables: what's the difference?

Build-time variables are baked into the bundle; runtime variables are read when the server starts.

Build-time vs runtime variables: what's the difference?
Build-timeRuntime
Read whenDuring the buildWhen the process starts
ExampleNEXT_PUBLIC_API_URLDATABASE_URL
Visible to browsersYes, never put secrets hereNo, server only
After changing itRebuild and redeployRedeploy or restart

Practices

What are the rules for handling secrets?

Five rules that prevent most leaks.

  • Never commit .env files: add them to .gitignore
  • Give previews their own values, such as a separate DATABASE_URL
  • Keep secrets out of NEXT_PUBLIC_* and other client-side variables
  • Rotate a secret immediately if it was ever committed or shared
  • Use managed database variables instead of copying passwords by hand

FAQ

Environment variable questions

The ones that come up every week.

Do I need to redeploy after changing an environment variable?

Yes. Running containers keep the values they started with, so redeploy for the app to read the new value.

Can preview deployments use different environment variables?

Yes. Set preview-specific values, such as a separate DATABASE_URL, so pull request previews never touch production data.

Where does DATABASE_URL come from on Runex?

When you add a managed database to a project, Runex injects its connection string as an environment variable. For an external database, add it yourself.

Are NEXT_PUBLIC_ variables secret?

No. Next.js inlines them into JavaScript that browsers download, so anyone can read them. Only put public values there.

Next step

Configure it once.

Set your variables, redeploy, and keep secrets out of Git for good.