skills/ render-oss/skills

render-env-vars

Configures environment variables, secrets, and env groups on Render. Use when the user needs to set env vars, wire secrets between services, create env groups, use generateValue, set sync: false, or troubleshoot missing or incorrect environment variable values in Blueprints or the Dashboard.

0
Installs
—
Rating
—
Success rate
4
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

4 files scannedscanner v1.2.0Oct 10, 2026

Content sha256 66d4da240b606f0e… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Environment Variables on Render

Before inspecting or changing environment variables, secrets, secret files, or environment groups, read references/environment-variables.md for the current documentation, source-of-truth, safety, and mutation workflow.

Blueprint wiring examples and language-specific application notes live under references/.

When to Use This Skill

Use this skill when users want to:

  • Add, change, or remove environment variables or secrets
  • Understand Dashboard vs Blueprint vs API/MCP flows
  • Use environment groups for shared configuration
  • Wire fromDatabase, fromService, fromGroup, sync: false, or generateValue in Blueprints
  • Debug missing vars, secret files, precedence, or platform-injected names

For full Blueprint authoring, pair with render-blueprints. For first-time deploys, render-deploy. For web service behavior and ports, render-web-services.

Blueprint Wiring (Summary)

After reading references/environment-variables.md, use references/wiring-reference.md for task-specific fromDatabase, fromService, and fromGroup examples. Consult render-blueprints for the complete Blueprint workflow.

Platform-Injected Variables

Use the current default-variable reference fetched through references/environment-variables.md instead of relying on a fixed catalog. Language-specific application notes remain in references/platform-variables.md.

Runtime-Specific Defaults

Always bind HTTP servers to 0.0.0.0 and PORT (or the stack’s documented port env) unless using a static site or custom Docker entrypoint.

  • When diagnosing a port-binding failure, first establish whether the service uses a native runtime or Docker and inspect its actual start command; the applicable defaults differ.
  • For a web service, PORT defaults to 10000. Prefer reading $PORT in the start command rather than hardcoding that number or setting PORT merely to match an arbitrary hardcoded port.
  • Native Python services currently receive GUNICORN_CMD_ARGS with a default bind to 0.0.0.0:10000. A custom Gunicorn start command should bind to 0.0.0.0:$PORT so the process and Render's health checks use the same port.

Common Issues

WEB_CONCURRENCY defaults differ for some older and newer services. When debugging worker counts, compare service creation date and explicit overrides, then confirm current behavior using references/environment-variables.md and references/platform-variables.md.

References

  • references/environment-variables.md — Current configuration docs, secret handling, groups, platform variables, and mutation safety
  • references/wiring-reference.md — Blueprint cross-resource wiring examples and workspace edge cases
  • references/platform-variables.md — Concurrency, native-runtime versus Docker behavior, and application parsing notes

Related Skills

  • render-blueprints — Full Blueprint authoring, validation, multi-service layouts
  • render-deploy — First deploy, repo requirements, MCP vs YAML
  • render-web-services — Ports, health checks, scaling behavior tied to env-driven servers

Current documentation retrieval

Whenever this skill directs you to consult current Render documentation:

  1. Retrieve the linked Markdown document directly with an available URL-fetching tool or HTTP client, such as curl. Do not substitute web-search summaries for the document.
  2. Confirm that retrieval succeeded and returned the expected document, then read its contents. Saving a file or printing its path is not sufficient.
  3. If the request fails or your tool cannot read the Markdown response, open and read the linked HTML version instead.
  4. If neither version can be retrieved, disclose that the current reference is unavailable and follow any topic-specific fallback in the skill. Use bundled guidance only for stable constraints, and do not guess at changeable platform details.

When a task requires multiple references, apply this workflow to each one and distinguish the documents you verified from those that remain unavailable.

Files

4
14.8 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from render-oss/skills8

render-background-workers

Sets up and configures background workers on Render for queue-based job processing. Use when the user needs to process async jobs, consume from a queue, run Celery/Sidekiq/BullMQ/Asynq/Oban workers, handle graceful shutdown with SIGTERM, wire a worker to Key Value, or choose between workers and cron

Scan passed 0
render-blueprints

Authors and validates render.yaml Blueprints for Render infrastructure. Use when the user needs to write or edit a render.yaml, wire services together with fromDatabase/fromService/fromGroup, set up projects and environments for multi-service apps, configure preview environments, validate against th

Scan passed 0
render-cli

Installs and uses the Render CLI for deploys, logs, SSH, psql, Blueprint validation, and automation. Use when the user needs to run Render CLI commands, script deploys in CI/CD, authenticate with an API key, query services non-interactively, or troubleshoot CLI auth issues. Trigger terms: render CLI

Needs review 0
render-cron-jobs

Configures and troubleshoots scheduled tasks on Render using cron job services. Use when the user needs to run something on a schedule, write a cron expression, set up a periodic job, migrate from Heroku Scheduler, choose between cron jobs and background workers, or fix a cron that isn't firing. Tri

Scan passed 0
render-debug

Debug failed Render deployments by analyzing logs, metrics, and database state. Identifies errors (missing env vars, port binding, OOM, etc.) and suggests fixes. Use when deployments fail, services won't start, or users mention errors, logs, or debugging.

Scan passed 0
render-deploy

Deploy applications to Render by analyzing codebases, generating render.yaml Blueprints, and providing Dashboard deeplinks. Use when the user wants to deploy, host, publish, or set up their application on Render's cloud platform.

Scan passed 0
render-disks

Attaches and manages persistent disks on Render services—mount paths, sizing, snapshots, file transfers, and single-instance constraints. Use when the user needs persistent storage, file uploads, a custom database on disk, CMS media storage, or needs to understand why their service can't scale horiz

Scan passed 0
render-docker

Builds and deploys Docker containers on Render—Dockerfiles, multi-stage builds, Blueprint Docker fields, private registries, layer caching, and platform constraints. Use when the user mentions Docker, Dockerfile, container images, multi-stage builds, container registry, GHCR, ECR, BuildKit, dockerCo

Scan passed 0

Related security skillsscan passed

auth

Implement JWT/cookie authentication and authorization in tRPC using createContext for user extraction, t.middleware with opts.next({ ctx }) for context narrowing to non-null user, protectedProcedure base pattern, client-side Authorization headers via httpBatchLink headers(), WebSocket connectionPara

Scan passed 0
security-and-hardening

Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data,

Scan passed 0
ponytail-audit

Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ranked, each finding explained in plain English. One-shot report, changes nothing. Use for "audit this codebase", "review the whole repo", "find

Scan passed 0
security-scan

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions. Use when auditing a .claude/ directory — CLAUDE.md, settings.json, MCP servers,

Scan passed 0
extension-to-functions-codebase

Skill for converting an installed Firebase Extension (or extension source) into a standalone Cloud Functions for Firebase codebase or publishable npm package, including V1 to V2 trigger upgrades, lifecycle hooks, and declarative security

Scan passed 0
securing-s3-buckets

Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Use when the user wants to secure a new bucket, audit an existing bucket, fix a security finding, configure encryption, or enable logging and monitoring. Do NOT

Scan passed 0