Lesson 14 / 21

Environment Config & Secrets

The same build behaves differently depending on where it runs.

One build, many configs

The same artifact should run in dev, staging, and production — only its configuration (API URLs, feature flags, log level) changes per environment, usually via environment variables.

Per-environment secrets

Production credentials must differ from staging credentials. Most CI systems let you scope secrets to an environment, so a staging deploy physically cannot read production's keys.

Never bake secrets into the artifact

If a secret is compiled into an image or bundle, it ships everywhere that artifact goes. Inject secrets at deploy/run time instead, never at build time.