Configuration
Environment variables and secrets
Set configuration and secret values for an app, and understand when they take effect.
Each app has two kinds of variables:
- Plain variables for configuration that isn't sensitive. Anyone with access to the app can read them.
- Secrets for API keys, tokens and passwords. They are stored in Secret Manager in your own Google Cloud project and are write-only: once set, nobody can read the value back in Elula.
Both are set as environment variables in your running app.
Set variables with the CLI
Run these from a folder linked to the app:
elula env set NODE_ENV=production elula env set LOG_LEVEL=info FEATURE_X=on # several at once elula env secret STRIPE_KEY=sk_live_xxx # a secret elula env list # plain values, secrets masked elula env list --json elula env delete FEATURE_X # works for plain variables and secrets
Secret names are stored in upper case: elula env secret api_key=... creates API_KEY.
elula env set GREETING="hello world".Set variables in the dashboard
Open the app's Environment tab, enter a key and value, tick secret for sensitive values, and click Add. Secrets show as •••••••• with a remove link.
When you create an app from a repository, the dashboard reads the repository's .env.example file (if any) and pre-fills its keys.
Changes apply on the next deploy
Saving a variable doesn't restart the app. The new value is used from the next deployment:
elula env set API_URL=https://api.example.com elula deploy
Each deploy sets the app's full variable list on Cloud Run. Variables you add to the service directly in the Google Cloud console are removed on the next deploy, so always change them through Elula.
Use variables locally
elula env pull # writes .env elula env pull --file .env.local
Plain variables are written with their values. Secrets are written as commented-out lines for you to fill in by hand:
API_URL=https://api.example.com # STRIPE_KEY=<secret — set manually>
.gitignore.Build-time variables
Variables starting with NEXT_PUBLIC_, VITE_, REACT_APP_ or NUXT_PUBLIC_ are passed into the build, because these frameworks bake them into the browser bundle. Set them before you deploy. Changing one needs a new build, which elula deploy does.
NEXT_PUBLIC_, VITE_ and REACT_APP_ variables are only used at build time. NUXT_PUBLIC_ variables are set at runtime too. If you use your own Dockerfile, declare each one with ARG. See Frameworks and Dockerfiles.
NEXT_PUBLIC_, VITE_, REACT_APP_ or NUXT_PUBLIC_ variables.Variables Elula manages
| Variable | Set by |
|---|---|
PORT | Cloud Run. The port your app must listen on (8080 by default). You can't set it as a variable; change it with elula scale --port |
DATABASE_URL | Elula, when the app has a managed database. See Databases |
NEXT_PUBLIC_URL / VITE_PUBLIC_URL | Elula, after a deploy, for apps whose framework is set to Next.js, React or Vue |
PORT, K_SERVICE, K_REVISION and K_CONFIGURATION are reserved by Cloud Run. If you set them, they are ignored.
If the app has a managed database, Elula's DATABASE_URL replaces any DATABASE_URL you set yourself.
How secrets are handled
- When you set a secret, Elula stores it in Secret Manager in your Google Cloud project.
- On each deploy, Elula reads the secret values and sets them as environment variables on the app.
elula env listand the dashboard never show secret values.- Deleting a secret also deletes it from Secret Manager.
Who can change variables
| Role on the app | Can do |
|---|---|
| Viewer | See variable names. Plain values are hidden, and elula env pull is refused |
| Editor, owner, workspace owner or admin | Add, change and delete variables and secrets |
See Team and roles.
Sharing a secret with a person
App secrets are configuration for the app. To send a password or key to a colleague, use a one-time link instead. See Sharing secrets.