Environment Variables Baked Into a Static Build Are Forever
Date Published

Any environment variable prefixed for client-side use gets inlined directly into the JavaScript bundle at build time — not read at runtime, not swappable after deploy. Change the value and nothing happens until the next build ships. Teams used to server-rendered apps, where an env var change is a restart away, are the ones most likely to get caught out by this.
The corollary that matters more than it sounds like it should: nothing inlined this way is actually secret, no matter how the variable is named. It's sitting in plain text in a file the browser downloads, which makes it exactly the wrong place for anything that needs to stay server-side.
The practical discipline is treating build-time and runtime configuration as genuinely different categories from the start — public, static values in the client bundle, and everything else kept server-side where a static export can't accidentally ship it to every visitor.