Nx
Prerequisites
Update dotenv-expand
package.json. It updates the dependency Nx uses to expand and decrypt environment values. Installing dotenv-expand as a separate top-level dependency is not enough.
{
"overrides": {
"nx": {
"dotenv-expand": "1000.0.0"
}
}
}
$ npm install
$ npm ls nx dotenv-expand
Encrypt
app with your project's name and directory.
$ dotenvx encrypt -f apps/app/.env
apps/app/.env and the updated package files, but never commit apps/app/.env.keys.
Set the private key
DOTENV_PRIVATE_KEY value from apps/app/.env.keys into your shell or CI secret configuration before starting Nx. Nx does not automatically read .env.keys. For a local Unix shell:
$ export DOTENV_PRIVATE_KEY='<your private key>'
Run Nx
process.env.
$ npx nx serve app
File selection and precedence
Nx continues to select application and target-specific files, such as apps/app/.env and apps/app/.env.serve.production. Keep Nx's environment loading enabled; do not set NX_LOAD_DOT_ENV_FILES=false for this setup.
Known limitation in Nx 23.2.1: an encrypted root value can incorrectly take precedence over the same variable in a project or target-specific file. Keep encrypted values in project files, or avoid defining the same variable in both an encrypted root file and a project file. Updating dotenv-expand alone does not fix this Nx precedence bug.
Want native support? Leave a comment on Nx PR #37219 to support the fix.
Expansion behavior
Without a private key, encrypted values remain ciphertext; this setup does not fail automatically for a missing key. An incorrect key causes decryption to fail. Decrypted values also undergo variable expansion and command substitution: $NAME and $(command) expressions are evaluated.
Using the dotenvx CLI instead
To let dotenvx load and decrypt a specific application's environment before Nx starts, use:
dotenvx run -f apps/app -- npx nx serve app
This alternative does not require the dependency override. Its injected values become inherited environment variables and take precedence over values Nx loads afterward.
For a shared root .env or separate .env.keys location with the CLI workflow, see Secrets in monorepos.