# Environments — Derived Rules > Derives from `domains/devops/first-principles.md` P1 (Reproducibility), P6 (Configuration as Code), P7 (Immutability). ## Environment Parity (P1 Reproducibility) - Dev, staging, prod are the same system, different data. - The same artifact runs in all three. The same config schema, different values. - "Works on my machine" is a parity failure. The machine is the pipeline. ## Configuration (P6 Configuration as Code) - Config is in the repo (default values) + environment overrides (secrets, endpoints). - No snowflake servers. No "this one is different because we edited it in prod." - Config changes are PRs, not SSH sessions. ## Secrets (P9 Secret Hygiene via security) - Secrets are per-environment. Dev secrets ≠ prod secrets. - Secrets come from a secrets manager (Vault, AWS Secrets Manager, Doppler), not env files in prod. - `.env` files are for local dev only. Prod uses the manager. ## Promotion (P5 Progressive Delivery via devops) - Code moves dev → staging → prod. Never the reverse. - A hotfix to prod is backported to staging and dev. Don't let them diverge. - Promotion is automated. The pipeline decides when code is ready, not a human. ## Data (P1, domains/data P8 Lifecycle Awareness) - Prod data is sacred. Never copy prod to dev without anonymization. - Staging uses prod-like data (anonymized, sampled). Dev uses synthetic data. - A test that runs against prod data is a test that can destroy prod data. Don't. ## What Violates Environment Discipline | Violation | Principle | |-----------|-----------| | "It works on my machine" | P1 Parity | | Manual config edit in prod | P6 Configuration as Code | | Dev secret reused in prod | P9 Secret Hygiene | | Copy prod DB to dev | P1, data P8 | | Hotfix in prod not backported | P5 (divergence) | | A snowflake server | P1, P6 |