Back to Projects
library

Env Loader

Advanced environment variable loader with multi-file precedence, auto type generation, cross-platform file watching, and system-wide secret sharing.

Env Loader

Overview

Env Loader (@explita/env-loader) is an enterprise-grade environment variable management toolkit built to streamline configuration across Node.js, Next.js, and multi-service architectures. Designed as a zero-dependency, modern alternative to standard dotenv packages, it resolves multi-file priority hierarchies: from centralized enterprise system secrets down to environment-specific and local overrides (.env.[NODE_ENV].local, .env.[NODE_ENV], .env.local, .env), guaranteeing deterministic and predictable configurations.

For enterprise infrastructure, Env Loader introduces system-wide secrets by automatically checking /etc/internal-secrets.env (service-specific database credentials and API tokens) and /etc/shared-secrets.env (shared cloud credentials across organizations). This single source of truth eliminates copying sensitive secrets across repositories, prevents accidental git commits, and resolves cross-platform paths seamlessly on both POSIX systems and Windows drive roots (\etc\...).

Developer experience is a core priority with automated code generation. With generateTypes: true, the loader inspects loaded variables and emits an env.d.ts declaration file that strongly types process.env in TypeScript with full IDE autocomplete. In addition, generateEnvFile: true can emit a centralized env.ts exporting typed constants. When paired with watch: true, modifying environment variables triggers live in-memory reload and automatically signals dev servers (Next.js, Vite, tsx, nodemon) to reload without manual intervention.

Env Loader supports zero-boilerplate side-effect imports (import "@explita/env-loader/auto" and import "@explita/env-loader/auto/watch") alongside a rich programmatic API with EnvLoader.loadWithPrecedence(), EnvLoader.loadSystemAndApp(), getEnv(), and hasKeys(). The watcher features dual-engine resilience, leveraging chokidar when installed with a graceful fallback to Node's native fs.watch. Sensitive credentials (keys, secrets, tokens, passwords) are automatically masked in verbose logs to prevent leaks in CI/CD pipelines.

Tech Stack

backend

TypeScriptNode.js@explita/env-loader

Tags

#TypeScript#Environment#Dotenv#Configuration#Secrets#Next.js#Node.js#NPM Package#Library