Codebase, dependencies, and config
Factors I–III — one codebase, explicit deps, and config in the environment.
I. Codebase
One codebase tracked in revision control; many deploys. Shared libraries become their own codebases. Multiple apps in one mega-repo can work with clear boundaries — multiple divergent forks of the same app do not.
II. Dependencies
Declare dependencies explicitly and isolate them (lockfiles, containers, language envs). Do not assume system-wide packages on the host. The build must be reproducible on a clean machine or CI runner.
III. Config
Config that varies between deploys (credentials, hosts, feature toggles per env) lives in the environment — env vars, platform secrets, mounted config — not in the code repo.
Code can hold non-secret constants. Secrets in git are an incident. “Config files copied by hand to prod” breaks auditability.
Senior practice today
- Twelve-factor config maps cleanly to K8s ConfigMaps/Secrets and sealed/external secret stores
- Prefer typed config loading with fail-fast on missing required keys
- Separate build-time flags from runtime config deliberately
If you need different code per environment, the factor is already violated.