Do I have to add .env file to versioning in react project?

Viewed 1340

I have seen some medium blogs and StackOverflow answers that I shouldn't add .env file to the versioning.

I quite understand why that is needed.

But how about when dealing with a Reactjs project?

Reactjs is for the frontend and all the environment variables are public even it is bundled for production and anyone can read it using a web browser.

I have 2 env files, .env.production for production and .env.staging for staging. The environment variable values are put to the bundled version while building. These files are the same across all other team members.

Actually there is no secret at all in these files.

The question is:

Should I add these 2 files to versioning or do I have to distribute these files manually to other team members? Then why?

2 Answers

No.

Preferred way is to have a file called .env.sample This will contain all the keys with random or no values in it. Any developer who clones the repo, will get to know the env_vars that are needed to run/build the project.

Within the teams, have a secrets sharing mechanism. There are lots of tools available to solve this.

First time after cloning the repo, the developers needs to run cp .env.sample .env and copy the values from the secret manager.

Make sure to add .env to .gitignore so no-one accidently pushes the .env containing secrets to the repo.

No you don't. .env file should be put on server in a separated way. Otherwise whoever can access to your source code repository can read or even modify .env file.

Related