Applications read variables at startup or runtime to select configuration without changing source code. Deployment systems can inject ports, feature settings, endpoints, and secret references per environment. Sensitive values still need access controls because child processes, logs, or diagnostics may expose them.