Skip to content

Configuration

Environment variables and secrets

Set configuration and secret values for an app, and understand when they take effect.

Each app has two kinds of variables:

  • Plain variables for configuration that isn't sensitive. Anyone with access to the app can read them.
  • Secrets for API keys, tokens and passwords. They are stored in Secret Manager in your own Google Cloud project and are write-only: once set, nobody can read the value back in Elula.

Both are set as environment variables in your running app.

Set variables with the CLI

Run these from a folder linked to the app:

elula env set NODE_ENV=production
elula env set LOG_LEVEL=info FEATURE_X=on     # several at once
elula env secret STRIPE_KEY=sk_live_xxx       # a secret
elula env list                                # plain values, secrets masked
elula env list --json
elula env delete FEATURE_X                    # works for plain variables and secrets

Secret names are stored in upper case: elula env secret api_key=... creates API_KEY.

Note: Quote values that contain spaces or shell characters: elula env set GREETING="hello world".

Set variables in the dashboard

Open the app's Environment tab, enter a key and value, tick secret for sensitive values, and click Add. Secrets show as •••••••• with a remove link.

When you create an app from a repository, the dashboard reads the repository's .env.example file (if any) and pre-fills its keys.

Changes apply on the next deploy

Saving a variable doesn't restart the app. The new value is used from the next deployment:

elula env set API_URL=https://api.example.com
elula deploy

Each deploy sets the app's full variable list on Cloud Run. Variables you add to the service directly in the Google Cloud console are removed on the next deploy, so always change them through Elula.

Use variables locally

elula env pull                  # writes .env
elula env pull --file .env.local

Plain variables are written with their values. Secrets are written as commented-out lines for you to fill in by hand:

API_URL=https://api.example.com
# STRIPE_KEY=<secret — set manually>
Warning: Don't commit the generated file. Add it to .gitignore.

Build-time variables

Variables starting with NEXT_PUBLIC_, VITE_, REACT_APP_ or NUXT_PUBLIC_ are passed into the build, because these frameworks bake them into the browser bundle. Set them before you deploy. Changing one needs a new build, which elula deploy does.

NEXT_PUBLIC_, VITE_ and REACT_APP_ variables are only used at build time. NUXT_PUBLIC_ variables are set at runtime too. If you use your own Dockerfile, declare each one with ARG. See Frameworks and Dockerfiles.

Warning: Anything in a browser bundle is public. Never put secrets in NEXT_PUBLIC_, VITE_, REACT_APP_ or NUXT_PUBLIC_ variables.

Variables Elula manages

VariableSet by
PORTCloud Run. The port your app must listen on (8080 by default). You can't set it as a variable; change it with elula scale --port
DATABASE_URLElula, when the app has a managed database. See Databases
NEXT_PUBLIC_URL / VITE_PUBLIC_URLElula, after a deploy, for apps whose framework is set to Next.js, React or Vue

PORT, K_SERVICE, K_REVISION and K_CONFIGURATION are reserved by Cloud Run. If you set them, they are ignored.

If the app has a managed database, Elula's DATABASE_URL replaces any DATABASE_URL you set yourself.

How secrets are handled

  • When you set a secret, Elula stores it in Secret Manager in your Google Cloud project.
  • On each deploy, Elula reads the secret values and sets them as environment variables on the app.
  • elula env list and the dashboard never show secret values.
  • Deleting a secret also deletes it from Secret Manager.

Who can change variables

Role on the appCan do
ViewerSee variable names. Plain values are hidden, and elula env pull is refused
Editor, owner, workspace owner or adminAdd, change and delete variables and secrets

See Team and roles.

Sharing a secret with a person

App secrets are configuration for the app. To send a password or key to a colleague, use a one-time link instead. See Sharing secrets.