# How can you have private environment variables outside of dev.nix?

**URL:** <https://community.firebasestudio.dev/t/how-can-you-have-private-environment-variables-outside-of-dev-nix/279>\
**Category:** General\
**Created:** [May 24, 2024, 3:02pm UTC](https://community.firebasestudio.dev/t/how-can-you-have-private-environment-variables-outside-of-dev-nix/279 "2024-05-24T15:02:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![treeder](https://sea2.discourse-cdn.com/flex002/user_avatar/community.firebasestudio.dev/treeder/32/215_2.png) [@treeder](https://community.firebasestudio.dev/u/treeder)\
**Post date:** [May 24, 2024, 3:02pm UTC](https://community.firebasestudio.dev/t/how-can-you-have-private-environment-variables-outside-of-dev-nix/279/1 "2024-05-24T15:02:55Z")

</div>

Codespaces has secrets that you set that aren’t checked into git or put into a config file. Is there any way to do something like that?

---

<div class="post-metadata">

**Author:** ![kirupa](https://sea2.discourse-cdn.com/flex002/user_avatar/community.firebasestudio.dev/kirupa/32/4_2.png) [@kirupa](https://community.firebasestudio.dev/u/kirupa)\
**Post date:** [May 25, 2024, 9:48pm UTC](https://community.firebasestudio.dev/t/how-can-you-have-private-environment-variables-outside-of-dev-nix/279/2 "2024-05-25T21:48:48Z")

</div>

Hi @treeder - one of the items we are actively looking at it is using Cloud Secret Manager for managing private values: [Secret Manager &nbsp;|&nbsp; Google Cloud](https://cloud.google.com/security/products/secret-manager)

If we go that route, would that work for what you are trying to do?

Cheers,  
Kirupa

---

<div class="post-metadata">

**Author:** ![treeder](https://sea2.discourse-cdn.com/flex002/user_avatar/community.firebasestudio.dev/treeder/32/215_2.png) [@treeder](https://community.firebasestudio.dev/u/treeder)\
**Post date:** [May 27, 2024, 1:22pm UTC](https://community.firebasestudio.dev/t/how-can-you-have-private-environment-variables-outside-of-dev-nix/279/3 "2024-05-27T13:22:48Z")

</div>

Seems like that could work. Not sure if having it tied to a particular GCP project would be a pain or not though, would have to think that through. I’d likely end up having a lot of GCP projects that would only be used for the secret manager.

---

<div class="post-metadata">

**Author:** ![Sunny](https://sea2.discourse-cdn.com/flex002/user_avatar/community.firebasestudio.dev/sunny/32/85_2.png) [@Sunny](https://community.firebasestudio.dev/u/Sunny)\
**Post date:** [June 15, 2024, 1:14am UTC](https://community.firebasestudio.dev/t/how-can-you-have-private-environment-variables-outside-of-dev-nix/279/4 "2024-06-15T01:14:59Z")

</div>

Sorry for reviving a old post, but I found a workaround, hope this would help someone (or at least future me)  
`dev.idx`

```auto
let
  secrets = import ./secrets.nix;
in
{ pkgs, ... }: {
  env = pkgs.lib.recursiveUpdate {
    # Normal environment variables here
  } secrets;
  # Your config

```

`secrets.nix`

```auto
{
    PORT=3000;
}

```

---

<div class="post-metadata">

**Author:** ![Sunny](https://sea2.discourse-cdn.com/flex002/user_avatar/community.firebasestudio.dev/sunny/32/85_2.png) [@Sunny](https://community.firebasestudio.dev/u/Sunny)\
**Post date:** [June 15, 2024, 11:52am UTC](https://community.firebasestudio.dev/t/how-can-you-have-private-environment-variables-outside-of-dev-nix/279/5 "2024-06-15T11:52:03Z")

</div>

Forgot to mention, remember to add `secrets.nix` onto `.gitignore`
