0Pricing
Claude Architect · บทเรียน

ความลับด้วยตัวแปรสภาพแวดล้อม

อ้างอิง ${GITHUB_TOKEN} และอย่าคอมมิตโทเค็น

ความลับด้วยตัวแปรสภาพแวดล้อม เป็นบทเรียน Claude Architect ฟรีบน CoddyKit นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Claude Architect และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Claude Architect มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

Why Secrets Don't Belong in Config

MCP servers connect Claude to real systems — GitHub, databases, internal APIs. Each connection needs credentials: tokens, API keys, passwords.

The architect's rule is absolute: secrets never live in committed files. Your .mcp.json (project scope, shared in version control) declares which servers exist and how to launch them — but a raw token written there is now in your git history forever.

The clean pattern is to reference a secret by environment-variable name and let the runtime resolve it. This lesson shows how MCP does exactly that with ${GITHUB_TOKEN}.

The Two MCP Scopes

MCP configuration lives in two distinct scopes, and the distinction drives where secrets are safe:

  • Project scope — .mcp.json at the repo root. Shared via VCS so the whole team gets the same servers.
  • User scope — ~/.claude.json. Personal, on your machine only, NOT shared.

Because project scope is committed, anything you put in .mcp.json is visible to everyone with repo access — including a leaked clone. That is precisely why a token's value must never appear there; only a reference to an env var may.

Referencing a Secret with ${VAR}

In .mcp.json you pass credentials through the server's env block, using ${VAR} expansion. The literal text ${GITHUB_TOKEN} is committed safely — the real token is resolved from the environment at launch time.

Here the GitHub MCP server receives its token without the secret ever touching the file.

{
  "mcpServers": {
    "github": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-github"],
      "env": {
        "GITHUB_PERSONAL_ACCESS_TOKEN": "${GITHUB_TOKEN}"
      }
    }
  }
}

Where the Real Value Comes From

The reference ${GITHUB_TOKEN} is inert until the runtime supplies the actual value. You provide it through your shell environment — typically from a local, git-ignored .env file or your OS secret store.

The token is set outside the repo. The committed config stays clean; each developer (and each CI runner) injects their own value.

# .env — git-ignored, never committed
export GITHUB_TOKEN="ghp_realSecretValueLivesOnlyHere"

# load it into the shell before launching Claude Code
source .env

Lock the Door: .gitignore

Referencing an env var is only half the defense. You must also guarantee the file holding the real value never gets committed.

Add your secret files to .gitignore. Commit an example file with placeholder names so teammates know which variables to set — without ever shipping the values.

# .gitignore
.env
.env.local
*.secret

# .env.example  (THIS one is committed — names only, no values)
GITHUB_TOKEN=
DATABASE_URL=

Personal vs Shared Secrets

Scope also decides whose credential is used:

  • A shared service token the whole team uses can be referenced in project .mcp.json — each member still supplies the value via their own environment.
  • A purely personal token (your individual PAT) fits naturally with user scope ~/.claude.json, which isn't shared anyway.

Either way the principle holds: the file may contain the name; the environment supplies the value. Never invert that.

Prefer Community MCP Servers

For standard integrations — GitHub, Postgres, Slack, filesystem — prefer a maintained community MCP server over a custom one. They already implement the env-based secret handling correctly, expose proper Tools/Resources/Prompts, and return structured errors.

Writing your own server just to call GitHub means re-implementing auth and token handling you could inherit safely. Reserve custom servers for genuinely proprietary systems.

Secrets in CI/CD

In a pipeline there is no developer .env to source. Instead, your CI platform's encrypted secret store injects the variable into the job environment, and the same ${GITHUB_TOKEN} reference resolves identically.

This is why the reference pattern matters: one committed .mcp.json works locally and in CI, with the value sourced differently in each place — and never printed.

# GitHub Actions — value comes from encrypted repo secrets
jobs:
  review:
    runs-on: ubuntu-latest
    env:
      GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
    steps:
      - run: claude -p "/review" --output-format json

Least Privilege for Tokens

An MCP token inherits whatever permissions you granted it. A GitHub PAT scoped to repo can push code; one scoped to read:org cannot.

Mirror the architect's least-privilege habit from tool and subagent design: grant each token only the scopes its server actually needs. If ${GITHUB_TOKEN} ever leaks despite your safeguards, a tightly scoped, short-lived token limits the blast radius dramatically.

Rotation and Leak Response

Treat any committed secret as compromised — even after you delete it, it remains in git history. The only real fix is to revoke and rotate the credential at its source (GitHub settings), then re-issue a fresh one into your environment.

Because your config references ${GITHUB_TOKEN} rather than embedding a value, rotation is painless: revoke the old token, update the env var, relaunch. No code change, no commit.

# After rotating the token at the provider, just update the env value:
export GITHUB_TOKEN="ghp_freshlyRotatedValue"
# .mcp.json still references ${GITHUB_TOKEN} — nothing else changes

Putting It Together

The complete, exam-grade pattern for MCP secrets:

  • Declare the server in project .mcp.json (shared via VCS).
  • Reference the secret as ${GITHUB_TOKEN} in the env block — never the raw value.
  • Supply the value from a git-ignored .env locally and from an encrypted store in CI.
  • Ignore secret files; commit only an .env.example of names.
  • Scope tokens to least privilege and rotate on any suspicion.

Config is shareable; secrets are not. That separation is the whole game.

Quick Check: Sharing an MCP Config

Apply the secret-handling rules to a real team scenario.

Recap: Secrets with Environment Variables

Key takeaways:

  • MCP config has two scopes: project .mcp.json (shared via VCS) and user ~/.claude.json (personal).
  • Committed config may hold a reference like ${GITHUB_TOKEN} — never the token value.
  • Real values come from a git-ignored .env locally and an encrypted secret store in CI; commit only an .env.example of names.
  • Prefer community MCP servers — they handle env-based secrets correctly out of the box.
  • Scope tokens to least privilege; on any leak, revoke and rotate at the source — the reference pattern makes rotation a one-line env change.

Separate the shareable from the secret, and you've internalized the rule the exam is testing.

คำถามที่พบบ่อย

บทเรียน “ความลับด้วยตัวแปรสภาพแวดล้อม” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “ความลับด้วยตัวแปรสภาพแวดล้อม” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Claude Architect ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Claude Architect มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “ความลับด้วยตัวแปรสภาพแวดล้อม”

อ้างอิง ${GITHUB_TOKEN} และอย่าคอมมิตโทเค็น คุณปฏิบัติ Claude Architect ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Claude Architect หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Claude Architect บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน

บทเรียน “ความลับด้วยตัวแปรสภาพแวดล้อม” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Claude Architect นี้ได้ไหม

ได้ บทเรียน Claude Architect ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. เครื่องมือ ทรัพยากร และพรอมต์
  2. ขอบเขตโครงการเทียบกับผู้ใช้
  3. ความลับด้วยตัวแปรสภาพแวดล้อม
  4. เซิร์ฟเวอร์ชุมชนเทียบกับเซิร์ฟเวอร์กำหนดเอง
← กลับไปที่ Claude Architect