Environment Variables

The host environment exposed as process.env

JavaScript reads a snapshot of the host environment through process.env.

console.log(process.env.HOME);
process.env.MY_FLAG = "1";

The object is created once per realm. Its initial entries are writable, enumerable, and configurable. Guest code may mutate individual values or replace process.env with another object.

Guest changes remain inside JavaScript and do not update the host OS environment inherited by subprocesses.

Exposure

The default CLI exposes the host process environment. An embedding host may install a filtered or secret-backed provider before creating the realm. Denied and absent names both appear missing.

Elide does not synthesize NODE_ENV or guest-only ELIDE_* variables. Runtime configuration variables set by the host are ordinary visible entries unless a provider filters them.

Dotenv files used by project tooling are not merged into process.env automatically. Guest code can load one explicitly:

process.loadEnvFile(); // .env in the current directory
process.loadEnvFile("config/local.env");

Explicit loading mutates the guest environment object; it does not update the host OS environment.

Security

Treat process.env as sensitive input. The default CLI snapshot can include credentials and tokens. Use sandbox or embedding policy when guest code should not receive the complete environment.

There is no per-name CLI allowlist or denylist for environment variables.