Lesson 15 / 23
Environment Config & Secrets
Run one artifact in every environment and inject environment-specific configuration and secrets at deploy time.
One build, many configs
The same artifact should run in dev, staging, and production — only its configuration (API URLs, feature flags, log level) changes per environment, usually via environment variables.
Per-environment secrets
Production credentials must differ from staging credentials. Most CI systems let you scope secrets to an environment, so a staging deploy physically cannot read production's keys.
Never bake secrets into the artifact
If a secret is compiled into an image or bundle, it ships everywhere that artifact goes. Inject secrets at deploy/run time instead, never at build time.