Course Content
LangChain Mastery
7 sections · 109 lessons
What is the role of environment configuration in LangChain?
What you need to know
What belongs in configuration
| Kind | Examples |
|---|---|
| Secrets | Provider API keys, database passwords, LangSmith API key |
| Endpoints | Vector DB URL, Redis URL, internal tool APIs |
| Model choices | Chat model id, embedding model id, fallback model |
| Behaviour | Temperature, max tokens, retriever k, score threshold, timeouts |
| Observability | Tracing on or off, project name, sampling rate |
| Feature flags | Enable reranker, enable human approval |
One validated settings object
Python
1from pydantic import SecretStr2from pydantic_settings import BaseSettings, SettingsConfigDict34class Settings(BaseSettings):5 model_config = SettingsConfigDict(env_file=".env", extra="ignore")67 openai_api_key: SecretStr # from OPENAI_API_KEY8 chat_model: str = "openai:gpt-5.4-mini" # override per environment9 temperature: float = 0.010 retriever_k: int = 411 vector_db_url: str # required: startup fails if missing12 langsmith_tracing: bool = False1314settings = Settings()- Field names map to environment variables case-insensitively (
VECTOR_DB_URL→vector_db_url). SecretStrhides the value in logs andrepr(it prints as**********).- This is Pydantic v2 syntax; the old
class Config: env_file = ".env"is v1 style.
Then build models from settings in one place:
Python
from langchain.chat_models import init_chat_modelllm = init_chat_model(settings.chat_model, temperature=settings.temperature)Variables LangChain reads by itself
- Provider keys:
OPENAI_API_KEY,ANTHROPIC_API_KEY,GOOGLE_API_KEYand so on, used when you don't passapi_key=. - Tracing:
LANGSMITH_TRACING=true,LANGSMITH_API_KEY,LANGSMITH_PROJECT, optionallyLANGSMITH_ENDPOINTfor self-hosted andLANGSMITH_TRACING_SAMPLING_RATE. OlderLANGCHAIN_TRACING_V2/LANGCHAIN_API_KEYnames still appear in older code.
Good practice
.envfor local development only, and in.gitignore.- A secret manager (AWS Secrets Manager, GCP Secret Manager, Vault, Kubernetes secrets) in production.
- Different LangSmith projects per environment so dev noise doesn't mix with production traces.
- Validate at startup, not on the first request.
A real-life example
An HR bot ran in dev, staging and production. The model name was hard-coded in five files; staging accidentally used the expensive production model for two months, and a developer once committed an API key in a notebook.
The team moved to one Settings class. Staging now sets CHAT_MODEL to a small model and LANGSMITH_PROJECT=hr-bot-staging; production reads keys from the secret manager. A missing VECTOR_DB_URL now stops the pod at startup with a clear message instead of failing on the first employee's question. Changing the retriever k from 4 to 6 for an experiment became a config change reviewed in minutes.
Follow-up questions to expect
- "How do you rotate keys?" — Store them in a secret manager, read them at startup (or refresh periodically), and restart pods; never bake them into images.
- "How do you choose models per tenant?" — Keep defaults in config and a per-tenant override table; pass the chosen model into the factory.
- "How do you stop tracing sensitive environments?" —
LANGSMITH_TRACING=false, or hide inputs and outputs with the LangSmith client's masking options.