从环境变量加载机密信息
使用环境变量将密钥排除在源代码之外
从环境变量加载机密信息 是 CoddyKit 上的免费 Flask Academy 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Flask Academy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Flask Academy 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Secrets Do Not Belong in Code
API keys and passwords pasted into source files leak the moment you push to Git. Keep secrets out of your repository entirely.
The Twelve-Factor Idea
The twelve-factor approach stores config in the environment, so the same code ships everywhere with no edits.
Read One with os.environ
Use os.environ to read a variable. It raises a clear error if the key is missing, which is great for required secrets.
import os
key = os.environ["SECRET_KEY"]Optional Values with get
Use os.environ.get for optional settings and supply a fallback so your app still boots in development.
debug = os.environ.get("DEBUG", "0")Wire It into a Config Class
Read env vars right inside your Config class so every environment gets its secrets from the system, not the source.
SECRET_KEY = os.environ.get("SECRET_KEY")Set a Variable in the Shell
On your machine, export the value before running. The process inherits it, and Flask picks it up.
export SECRET_KEY=super-secretEverything Is a String
Env vars arrive as strings. Convert numbers and booleans yourself, since "0" is truthy in Python.
port = int(os.environ.get("PORT", "5000"))Fail Fast on Missing Secrets
In production, a missing secret should crash on startup, not midway. Fail fast so the problem is obvious immediately.
if not SECRET_KEY:
raise RuntimeError("SECRET_KEY required")Where the Platform Sets Them
Hosts like Heroku, Docker, and Kubernetes inject env vars at deploy time, so no secret ever sits in your image.
Generate a Strong Key
A SECRET_KEY should be long and random. Generate one with secrets.token_hex and store it as an env var.
import secrets
secrets.token_hex(32)Never Log a Secret
Avoid printing config that holds secrets. A stray log line in a dashboard exposes the very value you protected.
Quick Check
How should you handle a required secret that is missing in production?
Recap: Env Secrets
You read secrets from os.environ, gave optional ones defaults, converted types, and failed fast when required keys were missing. 🔐
常见问题解答
「从环境变量加载机密信息」课时是免费的吗?
是的 — 「从环境变量加载机密信息」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Flask Academy 课程的其余内容,请升级到 CoddyKit PRO。 Flask Academy 课程共包含 4 节课。
「从环境变量加载机密信息」这节课中我会学到什么?
使用环境变量将密钥排除在源代码之外 你通过在浏览器中直接运行的动手代码来练习 Flask Academy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Flask Academy 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Flask Academy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。
「从环境变量加载机密信息」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Flask Academy 课中编写并运行代码吗?
能。每节 Flask Academy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 各环境的配置类
- 从环境变量加载机密信息
- 在开发环境中使用 dotenv
- 切换调试与功能标志