Environment variables
Store configuration and secrets outside your function code, then read each one by key at run time with the Azion.env.get interface.
An environment variable is a key-value pair stored outside your function code. It holds a configuration value or a secret, such as an API key, a database credential, or an access token. The value never enters the codebase or a version control system. A function reads the value by its key at run time, so a new value takes no edit to the code.
Variable fields
An environment variable carries three fields:
| Field | Type | Description |
|---|---|---|
key | string | Name the function passes to Azion.env.get(). |
value | string | Value returned for that key. |
secret | boolean | Whether the value is confidential. |
Azion assigns each variable an ID when it is created. The --variable-id flag of Azion CLI names it on azion describe variables, azion update variables, and azion delete variables.
Environment variables are stored on the account, and an account holds a maximum of 100 of them. The 32 KB cap is measured per function rather than per account: it bounds the total size of all environment variables for a single function. For every Functions limit, refer to Limits.
Access from function code
A function reads a variable with the Azion.env.get() interface, which takes the key and returns the value:
The call returns a string. A key that does not exist returns undefined rather than an error, and the function continues with that undefined value. A handler written in the ES Modules pattern also receives env, the object that carries the environment variables and the bindings available to the function.
For the parameters, the return value, and a longer example, refer to Environment Variables interface. Azion Runtime also supports process.env for Node.js compatibility, covered in process.
Management interfaces
You create, list, change, and delete environment variables through the Azion API, with Azion CLI, and with the Azion Terraform provider, where the resource is azion_environment_variable.
Azion CLI carries one subcommand per operation: azion create variables, azion list variables, azion describe variables, azion update variables, and azion delete variables. The --key, --value, and --secret flags set the three fields, and --secret defaults to true. The --file flag reads the same three fields from a JSON file instead.
A variable whose key contains password, pwd, secret, key, hash, encrypted, passcode, auth, or token is sent as a secret by default.
The azion sync command reads the variables in a local .env file and sends them to your account. The --env flag sets the path to that file, and the default is .edge/.env.
A change to a variable does not reach a function that is already running. The function is redeployed for the new value to take effect.
For the attributes azion update variables accepts, refer to Variables.