Variables vs Secrets

Configuration Variables Versus Secrets

A region, a feature flag or a public URL is not secret. It belongs in a configuration variable, read as ${{ vars.NAME }}, stored in plain text, readable again in the settings, and printed in logs unmasked (Secret Hygiene). Variables have the same three levels and precedence, and a repository may hold 500 of them:

A repository variable and a production overrideShell
gh variable set CATALOG_REGION --body ap-southeast-1
gh variable set CATALOG_REGION --env production --body eu-west-1
gh variable list; gh variable list --env production
Output
CATALOG_REGION  ap-southeast-1  2026-09-25T12:14:59Z
CATALOG_REGION  eu-west-1       2026-09-25T12:15:17Z

A change applies to the next run without a commit. Keep versioned values in the workflow's env:, per-repository or per-environment values in variables, and anything that grants access in secrets.