Environment variables
A variable is configuration the application reads from its environment: log level, feature flag, a service's address. The value is visible on screen — it is not a secret.
For sensitive values, use secrets.
Declaring
- Open the project and go to Variables.
- Choose the scope: organization, project, or environment.
- Enter the name and the value.
- Save.
The screen shows the variable with a badge indicating which scope it was declared in.
Inheritance in plain sight
When the same name exists in more than one scope, the most specific one wins. The screen shows the whole chain, with the effective value highlighted:
Organization LOG_LEVEL = info
Project LOG_LEVEL = debug ← this is the one the application reads
Environment (not declared)
Without seeing the chain, changing LOG_LEVEL at organization level and seeing no effect would look like a platform defect.
Variables the platform supplies
The platform injects the values the application needs in order to work, among them:
| Variable | What it holds |
|---|---|
PORT | The service's port, which the application must listen on, on 0.0.0.0. Default 8080 |
HOME | /tmp — the only writable directory while the application runs |
Your application should read the port from the environment rather than hard-coding a number. EXPOSE in the Dockerfile does not change the port. See How the application runs.
Changing and removing
- Changing replaces the value in the scope where it was declared.
- Removing deletes the declaration in that scope. If the same name exists in a more general scope, that one takes over — the screen shows which value becomes effective.
When it takes effect
On the next deployment. The screen warns when a change has been declared and not yet applied. To apply it now, deploy the service — the new version uses the same image with the new configuration.
Good practice
- Declare at the most general scope that still makes sense: what applies to every project belongs at the organization.
- Use the environment scope only for what genuinely differs between environments.
- A sensitive-sounding name is not a secret. If the value is sensitive, the right object is a secret, even when the name looks harmless.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.