It must be an environment variable of the location where it will be executed. If it is in the developer's machine, he must fill it in along with his usernames and passwords. If it's the case of an automated deploy/delivery, like a github action, you should use a github "repository secret" to manage your .env files.