Your application needs environment variables.
That's normal.
Your Git repository does not need your secrets.
That's different.
What's Inside .env?
A typical file might contain:
DATABASE_URL=... API_KEY=... JWT_SECRET=...
These values can provide access to important services.
If you commit them to a public repository, anyone who can see the repository may be able to use them.
Use .gitignore
A common approach is:
.env .env.local .env.production
in your .gitignore where appropriate.
Then keep the actual values in your hosting environment.
What If You Already Committed a Secret?
Deleting the file isn't enough.
Git history may still contain the previous version.
If a real credential was exposed:
Revoke it Generate a new credential Update your environment Review the repository history Check for other exposed secrets Hosting Platforms Provide Environment Configuration
Production secrets should be supplied through the deployment environment rather than committed to source control.
Hostwares supports environment variables through the dashboard, AI interface, and API.
Be Careful With Logs Too
Secrets shouldn't appear in logs either.
For example, avoid:
console.log(process.env.API_KEY);
Even if the repository is private, logs can have different access controls.
The Rule
Your Git repository should contain the instructions for your application.
It shouldn't contain the keys to your production infrastructure.
Code belongs in Git. Secrets belong in secret configuration.