Skip to content

Master Environment Variables Reference Matrix ​

This document is the authoritative engineering specification for all environment variables, public build arguments, and server secrets across the Debelu platform. Grounded directly in debelu-backend/.env.example, apps/storefront/.env.example, debelu-marketing/.env.example, and CI/CD deployment configurations, this matrix defines scope, sensitivity, validation formats, and cross-surface alignments.


1. Security Architecture & Boundary Principles ​

Debelu enforces strict separation between public client-side environment configurations and confidential server-side secrets.

mermaid
graph TD
    subgraph BrowserClientPerimeter [Client Browser & Mobile Sandbox]
        StorefrontClient["apps/storefront (Vite)<br/>Only VITE_* Variables Inlined"]
        MarketingClient["debelu-marketing (Next.js)<br/>Only NEXT_PUBLIC_* Inlined"]
    end

    subgraph ServerSecretPerimeter [Confidential Server Infrastructure]
        BackendAPI["debelu-backend (Railway/Node.js)<br/>SUPABASE_SERVICE_ROLE_KEY<br/>PAYSTACK_SECRET_KEY<br/>GEMINI_API_KEY"]
        EdgeFunctions["Supabase Deno Edge Workers<br/>VAPID_PRIVATE_KEY<br/>META_APP_SECRET"]
        GitHubActions["GitHub Actions Secrets Store<br/>Deployment & Cloud Tokens"]
    end

    BrowserClientPerimeter -.->|Strictly Forbidden from Storing| ServerSecretPerimeter

1.1 Core Rules ​

  1. Public Key Prefixing: Only variables prefixed with VITE_ (Vite) or NEXT_PUBLIC_ (Next.js) are bundled into client JavaScript. Any variable without these prefixes is inaccessible to frontend bundles.
  2. Zero Secrets in Client Bundles: Secret keys (PAYSTACK_SECRET_KEY, SUPABASE_SERVICE_ROLE_KEY, GEMINI_API_KEY, R2_SECRET_ACCESS_KEY) must NEVER be assigned VITE_ or NEXT_PUBLIC_ prefixes. Client bundles undergo automated CI scans to detect secret leakage.
  3. Fail-Closed Verification: Backend services validate mandatory environment variables at boot via Zod schemas, halting execution with exit code 1 if critical secrets are omitted.

2. Backend API Service (debelu-backend) ​

Configured via debelu-backend/.env (local) or Railway environment variables (production).

Variable NameSensitiveRequiredTarget / DefaultPurpose & Architectural Rules
NODE_ENVNoYesproduction | developmentEnables production optimizations, structured JSON logging, and Sentry sampling.
PORTNoYes8000 (or injected by Railway)TCP listening port for the Express HTTP server.
SUPABASE_URLNoYeshttps://xyzproject.supabase.coRemote Supabase project API gateway endpoint.
SUPABASE_SERVICE_ROLE_KEYYesYeseyJhbGciOiJIUzI1Ni...High Privilege: Bypasses PostgreSQL Row-Level Security for administrative queries.
SUPABASE_ANON_KEYNoYeseyJhbGciOiJIUzI1Ni...Public API key used for executing stored procedures on behalf of authenticated users.
SUPABASE_JWT_SECRETYesYes64-char HexadecimalCryptographic secret utilized to verify Supabase JWT auth tokens locally.
DATABASE_URLYesYespostgresql://postgres:...Direct PostgreSQL connection string for database migrations and connection pooling.
PAYSTACK_SECRET_KEYYesYessk_live_... / sk_test_...Financial Secret: Authorizes Paystack checkout payments, verification, and transfers.
PAYSTACK_DVA_BANKNoYeswema-bank (prod) / test-bankDefault commercial banking partner for dedicated virtual account (DVA) top-ups.
GEMINI_API_KEYYesYesAIzaSy...Authorizes Google AI Studio API calls for the Nduzi AI assistant.
GEMINI_MODELNoNogemini-2.5-flashConfigures the underlying Gemini language model identifier.
R2_ACCOUNT_IDYesNo32-char HexadecimalCloudflare account identifier for the R2 image storage bucket.
R2_ACCESS_KEY_IDYesNo32-char StringS3-compatible access key ID for Cloudflare R2 bucket.
R2_SECRET_ACCESS_KEYYesNo64-char StringS3-compatible secret access key for Cloudflare R2 bucket.
R2_PUBLIC_BUCKETNoNodebelu-product-imagesName of the R2 bucket hosting public product catalog images.
R2_PUBLIC_URLNoNohttps://cdn.debelu.comCDN base URL serving cached product images.
REDIS_URLYesNorediss://default:pwd@host:portRedis connection string for BullMQ distributed queues and cluster-wide rate limiting.
ALLOWED_ORIGINSNoYeshttps://debelu.com,https://app.debelu.com,https://admin.debelu.comWhitelist of client web origins allowed to pass CORS checks.
MAINTENANCE_JOBSNoNoon (or off)Controls in-process housekeeping cron execution (jobs/maintenance.ts).
WHATSAPP_WEBHOOK_VERIFY_TOKENYesNoRandom 32-char StringVerification token used during Meta WhatsApp Cloud API webhook registration.
META_APP_SECRETYesNoMeta App SecretShared secret used to verify Meta WhatsApp webhook HMAC signatures.
TERMII_API_KEYYesNoTermii KeyAPI key for Termii SMS gateway (used for campus verification PINs).
TERMII_BASE_URLNoNohttps://api.ng.termii.comBase URL for Termii SMS and wallet balance queries.
GIT_SHANoNoCommit SHAGit commit hash injected by CI for /health diagnostics.
SENTRY_DSNNoNoSentry DSN URLError reporting ingest URL for backend exceptions.

3. Storefront Web & Mobile Application (apps/storefront) ​

Configured via apps/storefront/.env.local (local) or Cloudflare Pages project settings (production).

Variable NameSensitiveRequiredTarget / DefaultPurpose & Description
VITE_SUPABASE_URLNoYeshttps://xyzproject.supabase.coSupabase gateway URL for client auth and realtime subscriptions.
VITE_SUPABASE_ANON_KEYNoYeseyJhbGciOiJIUzI1Ni...Public Supabase anon key; queries are strictly bounded by PostgreSQL RLS.
VITE_PAYSTACK_PUBLIC_KEYNoYespk_live_... / pk_test_...Public Paystack key for rendering inline checkout modals.
VITE_API_BASE_URLNoYeshttps://api.debelu.com/apiBase URL for debelu-backend REST endpoints.
VITE_MARKETING_URLNoYeshttps://debelu.comTarget origin for public marketing and login redirects.
VITE_APP_URLNoYeshttps://app.debelu.comCanonical storefront origin.
VITE_VENDOR_URLNoYeshttps://app.debelu.com/sellDeep-link root for merchant and seller views.
VITE_ADMIN_URLNoYeshttps://admin.debelu.comTarget URL for isolated staff origin redirections.
VITE_COOKIE_DOMAINNoYes.debelu.comShared root domain for cross-subdomain cookie session storage.
VITE_R2_PRODUCT_IMAGESNoNotrue | falseFeature toggle switching image uploads from Supabase to Cloudflare R2.
VITE_VAPID_PUBLIC_KEYNoNoBase64 URL-safe keyPublic VAPID key for Web Push browser notifications.
VITE_GIT_SHANoNoCommit SHAVersion tag displayed in mobile settings for troubleshooting.
VITE_SENTRY_DSNNoNoSentry DSN URLClient-side error reporting DSN for React exceptions.

4. Marketing & Public Website (debelu-marketing) ​

Configured via debelu-marketing/.env.local (local) or Vercel project settings (production).

Variable NameSensitiveRequiredTarget / DefaultPurpose & Description
NEXT_PUBLIC_SUPABASE_URLNoYeshttps://xyzproject.supabase.coPublic Supabase URL for login and registration forms.
NEXT_PUBLIC_SUPABASE_ANON_KEYNoYeseyJhbGciOiJIUzI1Ni...Public Supabase key for client authentication.
NEXT_PUBLIC_API_URLNoYeshttps://api.debelu.com/apiBackend API URL for public status checks.
NEXT_PUBLIC_STOREFRONT_URLNoYeshttps://app.debelu.comTarget destination for post-login session handoff.
NEXT_PUBLIC_POSTHOG_KEYNoNoPostHog Project API KeyProduct analytics tracking key.
NEXT_PUBLIC_POSTHOG_HOSTNoNohttps://app.posthog.comHost endpoint for PostHog telemetry ingestion.
SENTRY_AUTH_TOKENYesNoSentry Auth TokenRequired in CI/build environments for source map uploads.
SENTRY_DSNNoNoSentry DSN URLNext.js server, edge, and browser error tracking DSN.

5. Supabase Edge Functions Secrets ​

Managed via supabase secrets set or the Supabase Cloud dashboard.

Secret Key NameUsed By FunctionSensitivityPurpose & Description
PAYSTACK_SECRET_KEYpaystack-webhookHighVerifies HMAC SHA-512 signatures on inbound Paystack payment webhooks.
META_WHATSAPP_TOKENdeliver-notificationHighBearer token authorizing Meta WhatsApp Cloud API message delivery.
WHATSAPP_PHONE_NUMBER_IDdeliver-notificationNormalMeta registered phone identifier for transactional messaging.
TERMII_API_KEYdeliver-notificationHighAPI key for Termii SMS fallback delivery.
VAPID_PRIVATE_KEYdeliver-notificationHighPrivate cryptographic key for signing Web Push notification payloads.
SUPABASE_SERVICE_ROLE_KEYAll Edge FunctionsHighBypasses RLS to record webhook transactions and notification logs.

6. GitHub Actions CI/CD Secrets ​

Configured in GitHub Repository Settings (Settings $\rightarrow$ Secrets and variables $\rightarrow$ Actions).

Secret IdentifierTarget WorkflowPurpose & Description
CLOUDFLARE_API_TOKENstorefront-release.ymlAuthorizes deployment of static build assets to Cloudflare Pages.
CLOUDFLARE_ACCOUNT_IDstorefront-release.ymlCloudflare account identifier for Pages projects.
RAILWAY_TOKENbackend-deploy.ymlAPI token triggering Docker build and deployment on Railway.
VERCEL_TOKENmarketing-deploy.ymlAuthorizes deployment of Next.js marketing application to Vercel.
VERCEL_ORG_IDmarketing-deploy.ymlVercel team/organization identifier.
VERCEL_PROJECT_IDmarketing-deploy.ymlTarget Vercel project identifier for debelu.com.
SENTRY_AUTH_TOKENAll Build WorkflowsAuthenticates CLI source map uploads during release builds.

7. Cross-Surface Alignment Table ​

To prevent broken cross-domain links or authentication failures, the following values must align identically across all surfaces:

mermaid
flowchart LR
    subgraph ConfigAlignment [Cross-Surface Alignment Invariants]
        direction TB
        V1["Supabase URL & Anon Key"] -->|Identical In| SF["apps/storefront"]
        V1 -->|Identical In| MKT["debelu-marketing"]
        V1 -->|Identical In| ADM["debelu-admin"]
        
        V2["Paystack Keys"] -->|Public pk_* In| SF
        V2 -->|Secret sk_* In| BE["debelu-backend & Edge Functions"]
        
        V3["Origin URLs"] -->|Allowed in CORS| BE
        V3 -->|Used in Redirects| MKT & SF
    end

8. Document Revision History ​

RevisionDateLead AuthorScope of ChangesStatus
1.0.02026-10-05Principal DevOps EngineerComplete enterprise master environment variables specification covering all 4 surfaces, edge functions, CI secrets, and cross-surface alignments.Active Living Standard

Released under Proprietary Enterprise License.