How to see a Lambda function's environment variable names without showing their values
Updated · 2 min read
You want to know what a function is configured with (does it have a DATABASE_URL? which STRIPE_ keys?) without putting secret values on your screen, in your terminal's scrollback or in a screen share. The Lambda console shows names and values together, and AWS's API has no names-only option.
In the AWS console
Lambda → your function → Configuration → Environment variables lists every variable with its value in plain text, and there's no way to hide the values in that view. If you're sharing your screen, check what's on it before you click.
The exception is values encrypted with the console's encryption helpers (encryption in transit). Those show as ciphertext, and the function's code decrypts them itself.
With the AWS CLI
The API still returns names and values together, but the CLI's --query option can keep only the names before anything is printed:
aws lambda get-function-configuration --function-name my-function \
--query 'keys(Environment.Variables || `{}`)'The || `{}` part handles functions that have no variables at all, which would otherwise make keys() fail.
For every function in a region:
aws lambda list-functions --region us-east-2 \
--query 'Functions[].[FunctionName, join(`, `, keys(Environment.Variables || `{}`))]' \
--output textThe values still travel from AWS to your machine (the filtering happens inside the CLI), but they never reach your screen or your scrollback. Don't add --debug to these commands: it prints the full responses.
Why IAM can't hide the values
Anyone allowed to call lambda:GetFunctionConfiguration or lambda:ListFunctions receives the values too, including anyone with AWS's own ReadOnlyAccess policy. There's no permission for names without values. So:
- Keep secrets out of environment variables. Put them in Secrets Manager or SSM Parameter Store and put only the secret's name in the environment variable. Reading the secret then takes its own permission, which you give to the function and not to everyone who can look around the account.
- Treat "can list functions" as "can read their configuration". That includes monitoring tools and read-only roles you've given to third parties.
Or in Cloud GUI
Cloud GUI shows each function's environment variable names, never the values. AWS sends the values when Cloud GUI lists your functions (the same IAM limitation applies to everyone), so Cloud GUI drops them on its server before anything is shown or cached. Its security page says so plainly, along with everything else it can and can't see.