Skip to main content
Hostwares

Why Your Git Repository Should Not Contain .env

sowad sheikh··2 min read

Your application needs environment variables.

That's normal.

Your Git repository does not need your secrets.

That's different.

What's Inside .env?

A typical file might contain:

DATABASE_URL=... API_KEY=... JWT_SECRET=...

These values can provide access to important services.

If you commit them to a public repository, anyone who can see the repository may be able to use them.

Use .gitignore

A common approach is:

.env .env.local .env.production

in your .gitignore where appropriate.

Then keep the actual values in your hosting environment.

What If You Already Committed a Secret?

Deleting the file isn't enough.

Git history may still contain the previous version.

If a real credential was exposed:

Revoke it Generate a new credential Update your environment Review the repository history Check for other exposed secrets Hosting Platforms Provide Environment Configuration

Production secrets should be supplied through the deployment environment rather than committed to source control.

Hostwares supports environment variables through the dashboard, AI interface, and API.

Be Careful With Logs Too

Secrets shouldn't appear in logs either.

For example, avoid:

console.log(process.env.API_KEY);

Even if the repository is private, logs can have different access controls.

The Rule

Your Git repository should contain the instructions for your application.

It shouldn't contain the keys to your production infrastructure.

Code belongs in Git. Secrets belong in secret configuration.

Ready to deploy?

Launch your app on Hostwares — start for $1.00/mo with auto-scaling & global CDN.

Start for $1.00/mo

Ready to deploy? Start for $1.00/mo

Deploy now