How it works
Secrets are never stored in Runtime’s database. Values pass directly from your machine to Fly.io.
Declaring environment variables
Define env vars inruntm.yaml:
Field reference
Managing secrets
Set a secret
.env.local in your project directory.
List secrets
Get / remove
Security
Automatic protection
.env.local is automatically added to both .gitignore and .cursorignore:
- Secrets are never committed to git
- AI assistants cannot read secret values
Log redaction
Secrets markedsecret: true appear as [REDACTED] in logs:
Connections
Group related env vars as named connections:Using in code
- Python
- Node.js
Troubleshooting
Missing required environment variable
Missing required environment variable
Set the missing variable:
Secret env var cannot have default
Secret env var cannot have default
Secrets can’t have defaults. Remove the
default field:Secret value not updating
Secret value not updating
Redeploy after changing secrets: