The Sensitivity of .env Files
In modern web development, `.env` files contain environment variables required to run an application. These files typically store highly sensitive information, such as database connection strings, third-party API keys, and secret salts for cryptographic hashing.
Because of the high-value credentials they contain, `.env` files should never be committed to Git. A single accidental commit to a public repository can result in exposed databases, compromised cloud infrastructure, and massive financial liability.
Secrets Management vs. Transmission
When working with a team, you need a way to distribute environment variables. It is crucial to distinguish between long-term secrets management and one-time transmission.
For long-term storage and synchronization across a team or CI/CD pipelines, you should use dedicated secrets managers (like AWS Secrets Manager, Doppler, or HashiCorp Vault).
However, you may sometimes need to temporarily hand over a specific configuration to a contractor or a new developer before they are onboarded into the primary system. This is a transmission problem.
Practical Transmission Checklist
When you must transmit environment variables, avoid sending them directly through Slack or email, where they sit indefinitely in chat history. Instead, follow this secure handoff checklist:
- Remove Unnecessary Values: Never send the production `.env` file. Strip out any credentials the developer doesn't strictly need to run the application locally.
- Scope and Rotate: Generate temporary, limited-scope API keys specifically for local development.
- Use a Short Expiry: Use a tool like Hush to generate a one-time secret link with an explicit, short expiration time.
- Confirm Receipt: Send the link and confirm through a separate channel (Out-of-Band sharing) that the recipient successfully retrieved the file.
- Revoke and Rotate: If the developer leaves the project, immediately rotate any credentials they had access to.
Hush as a Transmission Tool
Hush is designed for the temporary transmission of sensitive data. It is not a secret manager, nor a source-control replacement. By encrypting the `.env` contents in the browser and consuming the payload upon access, Hush ensures that the configuration does not persist in email or chat logs.
For more details on how Hush works, read about our Security Model and How it Works or our guide on securely sharing API keys.