VibeKoding / Ensiklopedia ยท Fondasi KuatEnsiklopedia ยท Fondasi Kuat / An Introduction to Environment Variables and PATHAn Introduction to Environment Variables and PATH
VK

An Introduction to Environment Variables and PATHAn Introduction to Environment Variables and PATH

๐Ÿ“š Ensiklopedia ยท Fondasi KuatEnsiklopedia ยท Fondasi Kuat ๐ŸŒ Dual Bahasa (ID / EN) โšก VibeKoding Native

Ensiklopedia VibeKoding: An Introduction to Environment Variables and PATH.Ensiklopedia VibeKoding: An Introduction to Environment Variables and PATH.

> ๐Ÿ’ก Learning Guide: Every time you type git or python in the terminal, the system has to find where that program is located. Every time your code calls a large model API, the program needs to know which key to use. Both of these tasks rely on the same underlying mechanism โ€” environment variables.> ๐Ÿ’ก Learning Guide: Every time you type git or python in the terminal, the system has to find where that program is located. Every time your code calls a large model API, the program needs to know which key to use. Both of these tasks rely on the same underlying mechanism โ€” environment variables.

1. PATH: How Shell Finds the Command You Typed1. PATH: How Shell Finds the Command You Typed

PATH is a special environment variable that stores a list of directory paths (separated by colons). When you type git, Shell searches through these directories one by one for an executable file named git โ€” stopping as soon as it finds the first match.PATH is a special environment variable that stores a list of directory paths (separated by colons). When you type git, Shell searches through these directories one by one for an executable file named git โ€” stopping as soon as it finds the first match.

bash
$ echo $PATH /usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin

Select a command and observe how Shell searches through directories step by step:Select a command and observe how Shell searches through directories step by step:

Three key rules:Three key rules:

------

2. Motivation for needing to Restart the Terminal After Installing a Tool2. Motivation for needing to Restart the Terminal After Installing a Tool

When you install tools like nvm, Homebrew, or conda, the installation script automatically appends a line to ~/.zshrc to add its directory to PATH:When you install tools like nvm, Homebrew, or conda, the installation script automatically appends a line to ~/.zshrc to add its directory to PATH:

bash
# Content automatically written by the installer (example) export PATH="/usr/local/opt/python@3.12/bin:$PATH"

This line only executes when a new Shell starts. Already-open terminal windows are unaffected, so:This line only executes when a new Shell starts. Already-open terminal windows are unaffected, so:

bash
# Take effect immediately without restarting source ~/.zshrc

Common scenarios with AI development tools:Common scenarios with AI development tools:

bash
# Ollama / pipx installed but getting "command not found" which ollama # Check actual installation location # pip-installed CLI tool paths (add to PATH) # macOS: ~/Library/Python/3.x/bin # Linux: ~/.local/bin export PATH="$PATH:$HOME/.local/bin" # Recommended: use pipx to install CLI tools, manages PATH automatically pipx install aider-chat

------

3. Variable Scope: Who Can See ThOverview of Variable3. Variable Scope: Who Can See ThOverview of Variable

Environment variables are not broadcast to all programs โ€” each process holds its own copy, inherited from the parent process. Modifying your own copy does not affect the parent process.Environment variables are not broadcast to all programs โ€” each process holds its own copy, inherited from the parent process. Modifying your own copy does not affect the parent process.

The diagram below shows three levels. Export a new variable at the "User Level" and see whether it appears at the "Process Level":The diagram below shows three levels. Export a new variable at the "User Level" and see whether it appears at the "Process Level":

------

4. export: Determining Whether Child Processes Can Read a Variable4. export: Determining Whether Child Processes Can Read a Variable

When setting a variable, including or omitting export makes a completely different difference:When setting a variable, including or omitting export makes a completely different difference:

To make a variable persist across sessions, write the export statement into a configuration file:To make a variable persist across sessions, write the export statement into a configuration file:

bash
# macOS (zsh) echo 'export MY_VAR="value"' >> ~/.zshrc source ~/.zshrc # Takes effect immediately, no need to reopen the terminal # Linux (bash) echo 'export MY_VAR="value"' >> ~/.bashrc source ~/.bashrc

------

5. API Keys: Never Hardcode Them in Your Source Code5. API Keys: Never Hardcode Them in Your Source Code

When calling APIs from OpenAI, Anthropic, DeepSeek, and others, your key is essentially your "ID card + credit card." If it leaks, others can spend your quota โ€” and you foot the bill.When calling APIs from OpenAI, Anthropic, DeepSeek, and others, your key is essentially your "ID card + credit card." If it leaks, others can spend your quota โ€” and you foot the bill.

The most common mistake is hardcoding the key directly in source code:The most common mistake is hardcoding the key directly in source code:

------

6. Local Development: Managing Keys with .env Files6. Local Development: Managing Keys with .env Files

During local development, store keys in a .env file in the project root directory. Your code reads them via the dotenv library. .env must be added to .gitignore and never committed to Git.During local development, store keys in a .env file in the project root directory. Your code reads them via the dotenv library. .env must be added to .gitignore and never committed to Git.

Configure on the left, read on the right โ€” switch languages to see both approaches:Configure on the left, read on the right โ€” switch languages to see both approaches:

------

7. Production: Let the Runtime Platform Inject Keys7. Production: Let the Runtime Platform Inject Keys

.env is a convenience tool for the development phase. On servers and cloud platforms, the runtime environment should be responsible for injecting keys. The code itself should be completely unaware of where the keys are stored:.env is a convenience tool for the development phase. On servers and cloud platforms, the runtime environment should be responsible for injecting keys. The code itself should be completely unaware of where the keys are stored:

------

8. Practical Troubleshooting8. Practical Troubleshooting

command not foundcommand not found

bash
# Step 1: Check if it's in PATH which python3 # If there's output, it was found # Step 2: Find the program's actual location (macOS) brew list python | grep bin # Step 3: Add the directory to PATH export PATH="/found/path:$PATH" source ~/.zshrc # Remember to source after writing to config file

Installed Two Versions, Not Using the One I WantInstalled Two Versions, Not Using the One I Want

bash
which python # /usr/bin/python โ† Old system version, earlier in PATH # Put the new version's directory at the front of PATH export PATH="/usr/local/bin:$PATH" which python # /usr/local/bin/python โ† New version, now takes priority

Variable Is Set, But the Program Can't Read ItVariable Is Set, But the Program Can't Read It

CauseSolution
Forgot exportAdd export and try again
Modified ~/.zshrc but it didn't take effectRun source ~/.zshrc
Using .env but didn't install dotenvpip install python-dotenv / npm install dotenv
On server, variable only works in SSH sessionUse systemd EnvironmentFile instead

------

Quick GlossaryQuick Glossary

TermMeaning
PATHA list of directories where Shell searches for executables, colon-separated; order determines priority
exportMarks a variable as inheritable so child processes automatically get a copy
sourceRe-executes a configuration file in the current Shell, making changes take effect immediately
whichShows the executable file path for a command (the result of a PATH search)
.envA project-local configuration file for development keys; must be added to .gitignore
.env.exampleA template with complete variable names but empty values; safe to commit to Git
chmod 600File permission: only the owner can read and write; suitable for protecting key files
Secret ScannerGitHub and other platforms automatically scan for leaked keys and notify vendors to revoke them