Environment Variables and .env Files
Configure Compose services cleanly using environment variables, variable substitution, and a .env file so one Compose file works across dev, staging, and prod.
Environment Variables and .env Files is a free DevOps Bootcamp lesson on CoddyKit. This is lesson 4 of 4. Any 3 lessons of this learning path are free to read in full — after that, CoddyKit PRO unlocks every lesson, plus hands-on practice with a built-in code editor and a 24/7 AI tutor. It is part of the DevOps Bootcamp learning path, and your progress syncs across the web and the CoddyKit app. The DevOps Bootcamp course includes 4 lessons in total.
Why Externalize Config?
Hard-coding passwords and ports inside a Compose file is brittle and unsafe. Environment variables let you change behaviour per environment without editing the YAML.
- Keep secrets out of version control
- Reuse one Compose file everywhere
- Override values at runtime
The environment Key
Inside a service declare variables under environment as a map. These are injected into the container at start.
services:
db:
image: postgres:16
environment:
POSTGRES_USER: app
POSTGRES_PASSWORD: secretList Form
The same key also accepts a list of KEY=VALUE strings. Pick whichever form you find readable.
services:
db:
image: postgres:16
environment:
- POSTGRES_USER=app
- POSTGRES_PASSWORD=secretThe .env File
Compose automatically reads a file named .env in the project directory. Define values there once and reference them with ${VAR} substitution.
# .env
PG_USER=app
PG_PASS=secret
WEB_PORT=8080Variable Substitution
Use ${VAR} anywhere in the Compose file. Compose replaces it with the value from .env or the shell before parsing.
services:
db:
image: postgres:16
environment:
POSTGRES_USER: ${PG_USER}
POSTGRES_PASSWORD: ${PG_PASS}Default Values
Provide a fallback with ${VAR:-default}. If the variable is unset or empty, the default is used, keeping the stack working without a full .env.
ports:
- "${WEB_PORT:-80}:80"Required Variables
Use ${VAR:?message} to make a variable mandatory. Compose aborts with your message if it is missing, catching misconfiguration early.
environment:
API_KEY: ${API_KEY:?API_KEY must be set}The env_file Directive
To pass a whole file of variables straight into a container (not just substitution), use env_file. Each line becomes a container env var.
services:
api:
image: myapi:1.0
env_file:
- api.envPrecedence Rules
When a variable is defined in several places Compose applies an order. Shell environment beats .env; an explicit environment: entry beats env_file.
- Shell / CLI
-ewins - then
environment: - then
env_file - then image defaults
Inspecting Resolved Values
Run docker compose config to print the fully resolved Compose file with all substitutions applied. Great for verifying what will actually run.
docker compose configKeep Secrets Out of Git
Commit a .env.example with placeholders and add the real .env to .gitignore. For real production secrets prefer Docker secrets over env vars.
# .gitignore
.envQuick Check
How do default values work in substitution?
Recap
You can now configure Compose cleanly with environment data:
environment:injects variables per service- A
.envfile feeds${VAR}substitution :-gives defaults,:?marks required valuesdocker compose configshows the resolved result
This makes one Compose file portable across every environment.
Learn DevOps Bootcamp with an AI tutor — free
Write and run real code in your browser, get instant help from a 24/7 AI tutor, and pick up where you left off on the web or in the app.
- Courses
- 142
- Lessons
- 568
Frequently Asked Questions
Is the “Environment Variables and .env Files” lesson free?
Yes — any 3 lessons of the DevOps Bootcamp learning path, including “Environment Variables and .env Files”, are free to read in full here on the web. After that, CoddyKit PRO unlocks every lesson, plus interactive practice with a built-in code editor and a 24/7 AI tutor. The DevOps Bootcamp course includes 4 lessons in total.
What will I learn in “Environment Variables and .env Files”?
Configure Compose services cleanly using environment variables, variable substitution, and a .env file so one Compose file works across dev, staging, and prod. You practise DevOps Bootcamp with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start DevOps Bootcamp?
No prior experience is required. DevOps Bootcamp on CoddyKit is structured for beginners through advanced learners, so you can start here or from the beginning and move at your own pace. This is lesson 4 of 4.
How long does the “Environment Variables and .env Files” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this DevOps Bootcamp lesson?
Yes. Every DevOps Bootcamp lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- What is Docker Compose?
- Writing a Compose File
- Deploying Multi-Service Apps
- Environment Variables and .env Files