LangChain Mastery

Course Content

LangChain Mastery

7 sections · 109 lessons

What is the role of environment configuration in LangChain?


What you need to know

What belongs in configuration

KindExamples
SecretsProvider API keys, database passwords, LangSmith API key
EndpointsVector DB URL, Redis URL, internal tool APIs
Model choicesChat model id, embedding model id, fallback model
BehaviourTemperature, max tokens, retriever k, score threshold, timeouts
ObservabilityTracing on or off, project name, sampling rate
Feature flagsEnable reranker, enable human approval

One validated settings object

Python
from pydantic import SecretStrfrom pydantic_settings import BaseSettings, SettingsConfigDictclass Settings(BaseSettings):    model_config = SettingsConfigDict(env_file=".env", extra="ignore")    openai_api_key: SecretStr                  # from OPENAI_API_KEY    chat_model: str = "openai:gpt-5.4-mini"    # override per environment    temperature: float = 0.0    retriever_k: int = 4    vector_db_url: str                         # required: startup fails if missing    langsmith_tracing: bool = Falsesettings = Settings()
  • Field names map to environment variables case-insensitively (VECTOR_DB_URL → vector_db_url).
  • SecretStr hides the value in logs and repr (it prints as **********).
  • This is Pydantic v2 syntax; the old class Config: env_file = ".env" is v1 style.

Then build models from settings in one place:

Python
from langchain.chat_models import init_chat_modelllm = init_chat_model(settings.chat_model, temperature=settings.temperature)

Variables LangChain reads by itself

  • Provider keys: OPENAI_API_KEY, ANTHROPIC_API_KEY, GOOGLE_API_KEY and so on, used when you don't pass api_key=.
  • Tracing: LANGSMITH_TRACING=true, LANGSMITH_API_KEY, LANGSMITH_PROJECT, optionally LANGSMITH_ENDPOINT for self-hosted and LANGSMITH_TRACING_SAMPLING_RATE. Older LANGCHAIN_TRACING_V2 / LANGCHAIN_API_KEY names still appear in older code.

Good practice

  • .env for local development only, and in .gitignore.
  • A secret manager (AWS Secrets Manager, GCP Secret Manager, Vault, Kubernetes secrets) in production.
  • Different LangSmith projects per environment so dev noise doesn't mix with production traces.
  • Validate at startup, not on the first request.

A real-life example

An HR bot ran in dev, staging and production. The model name was hard-coded in five files; staging accidentally used the expensive production model for two months, and a developer once committed an API key in a notebook.

The team moved to one Settings class. Staging now sets CHAT_MODEL to a small model and LANGSMITH_PROJECT=hr-bot-staging; production reads keys from the secret manager. A missing VECTOR_DB_URL now stops the pod at startup with a clear message instead of failing on the first employee's question. Changing the retriever k from 4 to 6 for an experiment became a config change reviewed in minutes.

Follow-up questions to expect

  • "How do you rotate keys?" — Store them in a secret manager, read them at startup (or refresh periodically), and restart pods; never bake them into images.
  • "How do you choose models per tenant?" — Keep defaults in config and a per-tenant override table; pass the chosen model into the factory.
  • "How do you stop tracing sensitive environments?" — LANGSMITH_TRACING=false, or hide inputs and outputs with the LangSmith client's masking options.