Skip to content
LakeBench
ProblemsCommunityPricing
Sign inStart practicing
Back
  1. Home
  2. Interview prep
  3. Secrets with env_var

dbt · Macros, Packages & Advanced

Secrets with env_var

Mediumdbt-35
env_varsecretssecurityprofiles

Question

How should you handle secrets in dbt (env_var)?

Solution

Don't commit passwords, tokens, or private keys in git. Use `env_var` (and your secret manager / CI variables) so credentials are injected at runtime.

In profiles.yml

password: "{{ env_var('DBT_PASSWORD') }}"
user: "{{ env_var('DBT_USER') }}"

Optional default for non-secrets only:

schema: "{{ env_var('DBT_SCHEMA', 'dbt_dev') }}"

In project code

-- rare: API-related configs, never hardcode tokens
{{ config(snowflake_warehouse=env_var('DBT_WAREHOUSE')) }}

Prefer env for connection/profile concerns; keep models free of secrets entirely.

Mental model

Secret store / CI vars / local shell env
        |
   env_var('NAME')
        |
 profiles.yml / rare configs
        |
   warehouse auth

Practices

  • Different credentials for dev vs prod targets
  • Rotate credentials without editing SQL
  • Fail loudly if a required env var is missing (no silent empty password)

Interview tip: "dbt_project.yml is code; secrets are environment. env_var is the bridge."

PreviousNext