This commit is contained in:
2026-09-24 13:15:47 +05:30
parent bb14445e21
commit cf3e4ea159
5 changed files with 159 additions and 3 deletions

View File

@@ -465,10 +465,21 @@ func (c *Config) validate() error {
//
// APP_ENV is read from the real environment before any file, so a file cannot
// change which environment it is loaded for.
func loadEnvFiles() {
appEnv := env("APP_ENV", EnvLocal)
// `.env.secrets` is read FIRST and is the only one of these git does not track.
// godotenv never overwrites a value already set, so first read wins — which is
// what makes this file the place a key belongs. Every other file here is in the
// repository, so a secret written to one is a secret published; there was
// previously nowhere to put a key at all, and the answer was "export it in your
// shell every time", which is the kind of instruction people route around.
// envFileOrder is the read order, and the order is the rule: godotenv never
// overwrites a value already set, so whichever file names a variable first is
// the one that decides it.
func envFileOrder(appEnv string) []string {
return []string{".env.secrets", ".env." + appEnv, ".env"}
}
for _, name := range []string{".env." + appEnv, ".env"} {
func loadEnvFiles() {
for _, name := range envFileOrder(env("APP_ENV", EnvLocal)) {
if _, err := os.Stat(name); err != nil {
continue
}