Environment Management
Environment Management
Section titled “Environment Management”Introduction
Section titled “Introduction”Applications run in multiple environments — local development, preview/staging, and production. Each environment has different configuration, databases, and API keys.
Environment Types
Section titled “Environment Types”| Environment | Purpose | Database | API Keys |
|---|---|---|---|
| Development | Local coding | Local DB | Test keys |
| Preview | Testing changes | Staging DB | Staging keys |
| Production | Live users | Production DB | Production keys |
Managing Environment Variables
Section titled “Managing Environment Variables”# .env (committed — shared defaults)NEXT_PUBLIC_APP_URL=http://localhost:3000
# .env.local (not committed — local overrides)DATABASE_URL=postgresql://localhost:5432/myapp-devNEXTAUTH_SECRET=local-dev-secret
# .env.production (not committed — production values)DATABASE_URL=postgresql://prod-server:5432/myappNEXTAUTH_SECRET=prod-secretEnvironment Validation
Section titled “Environment Validation”function getEnvVar(key: string, required = true): string { const value = process.env[key]
if (!value && required) { throw new Error(`Missing required environment variable: ${key}`) }
return value ?? ''}
export const env = { databaseUrl: getEnvVar('DATABASE_URL'), nextAuthSecret: getEnvVar('NEXTAUTH_SECRET'), nextAuthUrl: getEnvVar('NEXTAUTH_URL'), siteUrl: getEnvVar('NEXT_PUBLIC_SITE_URL', false) || 'http://localhost:3000',}Environment-Specific Configuration
Section titled “Environment-Specific Configuration”export const isProduction = process.env.NODE_ENV === 'production'export const isDevelopment = process.env.NODE_ENV === 'development'export const isTest = process.env.NODE_ENV === 'test'
// Feature flags per environmentexport const features = { enableDebugTools: !isProduction, enableAnalytics: isProduction, logApiErrors: !isProduction,}Common Mistakes
Section titled “Common Mistakes”- Missing environment variables at runtime — Always validate required variables at startup.
- Committing production secrets — Add
.env.localand.env.productionto.gitignore. - Confusing build-time vs runtime variables —
NEXT_PUBLIC_variables are inlined at build time. Non-prefixed variables are only available on the server at runtime.
Best Practices
Section titled “Best Practices”- Validate required environment variables at application startup
- Use
env.tsto centralize and type all environment variables - Keep
.env.examplewith placeholder values (committed to Git) - Never commit
.env.local,.env.development, or.env.production - Use platform-specific settings (Vercel dashboard, Docker Compose) for deployment
Summary
Section titled “Summary”Manage environment variables through different .env files for development, preview, and production. Validate required variables at startup and centralize access through a typed env.ts module. Never commit secrets to version control.