Don't commit passwords, tokens, or private keys in git. Use `env_var` (and your secret manager / CI variables) so credentials are injected at runtime.
In profiles.yml
password: "{{ env_var('DBT_PASSWORD') }}"
user: "{{ env_var('DBT_USER') }}"Optional default for non-secrets only:
schema: "{{ env_var('DBT_SCHEMA', 'dbt_dev') }}"In project code
-- rare: API-related configs, never hardcode tokens
{{ config(snowflake_warehouse=env_var('DBT_WAREHOUSE')) }}Prefer env for connection/profile concerns; keep models free of secrets entirely.
Mental model
Secret store / CI vars / local shell env
|
env_var('NAME')
|
profiles.yml / rare configs
|
warehouse authPractices
- Different credentials for
devvsprodtargets - Rotate credentials without editing SQL
- Fail loudly if a required env var is missing (no silent empty password)
Interview tip: "dbt_project.yml is code; secrets are environment. env_var is the bridge."