mcloud-variables

작성자: medusajs

mcloud variables 명령어를 실행하여 Cloud 환경의 환경 변수를 나열하고 가져옵니다. 환경을 검사하거나 읽거나 내보낼 때 사용합니다.

npx skills add https://github.com/medusajs/medusa-agent-skills --skill mcloud-variables

Cloud CLI: Variables Commands

Execute mcloud variables commands to inspect and manage environment variables for Cloud environments.

Constraints

  • Never pass --reveal unless the user explicitly asks. Secret values appear in terminal scrollback, log aggregators, and process listings.
  • Variable changes need a deploy to apply. set/delete don't rebuild or redeploy. Run mcloud environments redeploy <env> for a runtime variable, or mcloud environments trigger-build <env> for a build variable (a redeploy reuses the existing image and won't pick up build-variable changes).
  • System variables can't be deleted, and delete requires --yes in non-interactive mode.
  • Looking up or creating a variable by key requires --project and --environment (or the equivalent in active context). Referencing by ID (var_...) works without project/environment context.
  • set and delete require mcloud CLI v0.1.10+.

Commands

variables list

List all environment variables for a Cloud environment.

mcloud variables list \
  --organization <org-id> \
  --project <project-id-or-handle> \
  --environment <environment-handle> \
  --json

Options:

  • -o/--organization <id> — Organization ID (falls back to active context)
  • -p/--project <id-or-handle> — Project ID or handle (falls back to active context)
  • -e/--environment <handle> — Environment handle (falls back to active context)
  • -t/--type <backend|storefront> — Which variable set to list (default: backend)
  • --scope <build|runtime> — Filter by scope; repeatable (default: both scopes)
  • --include-system — Include system variables Medusa auto-injects (default: false)
  • --reveal — Print secret values in plaintext instead of masking (use only when explicitly asked)
  • --dotenv — Output .env-formatted KEY=VALUE lines instead of a table
  • --json — Output as JSON

variables get

Retrieve a single variable by its ID (var_...) or key.

# By key (requires project + environment context)
mcloud variables get ADMIN_CORS \
  --organization <org-id> \
  --project <project-id-or-handle> \
  --environment <environment-handle> \
  --json

# By ID (works without project/environment context)
mcloud variables get var_01XYZ --json

Arguments:

  • variable — Variable ID (var_...) or key (required)

Options:

  • -o/--organization <id>, -p/--project <id-or-handle>, -e/--environment <handle>
  • -t/--type <backend|storefront> — Which variable set to read (default: backend)
  • --reveal — Print secret value in plaintext (use only when explicitly asked)
  • --json — Output as JSON

variables set

Create or update one or more variables. The CLI updates when you reference an existing key or a var_... ID, and creates otherwise.

# Single variable
mcloud variables set API_KEY pk_123 \
  --organization <org-id> \
  --project <project-id-or-handle> \
  --environment <environment-handle>

# Multiple at once
mcloud variables set -v API_KEY=pk_123 -v CLIENT_ID=my_app

# From a .env file
mcloud variables set --env-file .env

Arguments:

  • variable — Variable ID (var_...) or key to set (omit when using --var/--env-file)
  • value — Value to set (required when a variable argument is passed)

Options:

  • -o/--organization <id>, -p/--project <id-or-handle>, -e/--environment <handle>
  • -t/--type <backend|storefront> — Which variable set to write (default: backend)
  • -v/--var <KEY=VALUE|ID=VALUE> — A variable to set; repeatable
  • --env-file <path> — Set all variables from a .env file
  • --secret, --no-secret — Mark as secret (default: false for new variables)
  • --build, --no-build — Available at build time (default: false for new variables)
  • --runtime, --no-runtime — Available at runtime (default: true for new variables)
  • --json — Output as JSON

Redeploy (runtime) or trigger-build (build) afterward — see Constraints.

variables delete

Delete a variable by its ID (var_...) or key. Irreversible; system variables can't be deleted.

mcloud variables delete API_KEY \
  --organization <org-id> \
  --project <project-id-or-handle> \
  --environment <environment-handle> \
  --yes

Arguments:

  • variable — Variable ID (var_...) or key to delete (required)

Options:

  • -o/--organization <id>, -p/--project <id-or-handle>, -e/--environment <handle>
  • -t/--type <backend|storefront> — Which variable set to delete from (default: backend)
  • -y/--yes — Skip confirmation prompt (required in non-interactive mode)
  • --json — Output as JSON

Variable Fields (JSON)

FieldDescription
idVariable ID (var_...)
keyVariable name (e.g. ADMIN_CORS)
valueVariable value (masked if is_secret and --reveal not passed)
is_secretWhether the variable is treated as a secret
is_buildAvailable at build time
is_runtimeAvailable at runtime
environment_idThe environment ID this variable belongs to
sourceuser for user-set variables, system for auto-injected ones

Examples

# List all variables for the active environment
mcloud variables list --json

# List only runtime variables, including system ones
mcloud variables list --scope runtime --include-system --json

# List storefront variables
mcloud variables list --type storefront --json

# Get a variable by key (with active context)
mcloud variables get DATABASE_URL --json

# Get a variable by ID (no env context needed)
mcloud variables get var_01XYZ --json

# Set a single variable, then redeploy to apply (runtime)
mcloud variables set REDIS_URL redis://cache:6379
mcloud environments redeploy production

# Set a secret build-only variable, then trigger a build to apply
mcloud variables set STRIPE_SECRET_KEY sk_live_123 --secret --build --no-runtime
mcloud environments trigger-build production

# Set multiple variables from a .env file
mcloud variables set --env-file .env

# Delete a variable (irreversible — confirm before running)
mcloud variables delete OLD_FLAG --yes

# Only reveal secrets when user explicitly asks
mcloud variables get STRIPE_SECRET_KEY --reveal --json | jq -r '.value'

# Export all variables to a .env file (user must explicitly request --reveal)
mcloud variables list --reveal --dotenv > .env

# Check if a specific variable exists
mcloud variables list --json | jq '.[] | select(.key == "REDIS_URL")'

medusajs의 다른 스킬

creating-agents-in-medusa
medusajs
Medusa 프로젝트에서 내부 관리자용 AI 에이전트를 구축할 때 사용합니다. 이러한 에이전트는 고객이 아닌 판매자와 스토어 운영자가 사용합니다. 다음을 다룹니다…
mcloud-local
medusajs
로컬 머신에서 Cloud build를 재현하기 위해 mcloud local build를 실행합니다. 추적된 브랜치로 푸시하지 않고 빌드에 실패한 배포를 디버깅할 때 사용합니다,…
reviewing-prs
medusajs
Medusa 저장소의 GitHub 풀 리퀘스트를 검토합니다. PR 템플릿 준수 여부, 기여 가이드라인, 코드 규칙, 보안, 성능 등을 확인합니다…
writing-releases
medusajs
Medusa 릴리스에 대한 GitHub 릴리스 노트를 기존 스타일로 작성합니다. 커밋 및 PR 목록에서 초안 릴리스 설명을 생성할 때 사용합니다…
writing-tsdocs
medusajs
Medusa 코드베이스의 TypeScript 소스 파일에 TypeDoc(TSDoc) 주석을 추가하고 업데이트합니다. HTTP 유형, API 라우트, UI 컴포넌트, 데이터 모델, 서비스…를 다룹니다.
mcloud-deployments
medusajs
mcloud deployments 명령을 실행하여 배포 목록을 조회하고, 배포 세부 정보를 검색하며, 빌드 로그를 가져옵니다. 배포 목록을 확인하거나, 배포 상태를 점검할 때 사용합니다.
writing-docs
medusajs
Medusa 문서의 book, resources, ui, user-guide, cloud 프로젝트에 대한 MDX 파일을 작성하고 업데이트합니다. 문서 변경 사항을 적용할 때 사용합니다…
building-storefronts
medusajs
SDK 기반의 Medusa 스토어프론트 통합으로, React Query 패턴과 중요한 API 호출 규칙을 포함합니다. 모든 API 요청에는 항상 Medusa JS SDK를 사용해야 하며, 일반 fetch()는 사용하지 않습니다. fetch()는 필수 헤더(스토어 라우트의 publishable API 키, 관리자 라우트의 인증)가 누락되기 때문입니다. SDK 메서드에는 일반 JavaScript 객체를 전달하며, 본문 매개변수에 JSON.stringify()를 사용하지 않습니다. SDK가 자동으로 직렬화를 처리합니다. GET 요청에는 useQuery를, POST/DELETE 요청에는 useMutation을 사용합니다.