Environment variables
Environment variables live on the project, not in your repository. naro never reads a local .env without asking first.
Your .env is not uploaded on its own
naro checks whether .env.local, .env.production or .env exists — it does not open the file until you say yes. When it asks, values are masked: NEXT_PUBLIC_, VITE_, REACT_APP_ and PUBLIC_ variables are shown in full because they already ship inside your client bundle, and everything else shows four characters.
Set a variable
The value comes from a prompt or from stdin, never from an argument, so it does not land in your shell history.
naro env add DATABASE_URLproduction and preview
Every variable belongs to one of the two. A preview deploy never sees production values.
naro env add DATABASE_URL previewRead them back
naro env list masks secrets; --reveal opts into the values. naro env pull writes them to .env.local.
naro env listnaro env pullWhat a deploy tells you
A deploy reports the variables your source references that the project does not have. Add those before the build needs them.