page:guides:astro:configuration secrets

Configure environment and secrets for Astro

Summary

Configure environment variables and secrets for an Astro app on Ample. Values passed with --env or --env-file are stored encrypted and injected at runtime; the platform never prints them and ample.toml declares only variable names. The fixture proves delivery by reporting whether the secret is set without echoing it.

Prerequisites

Tested Configuration

Workflow Steps

  1. Declare, do not commit
    In ample.toml declare SMTP_KEY = { secret = true } style entries; never put literal secrets in the manifest.
  2. Pass values on deploy
    Use --env KEY=value (repeatable) or --env-file .env.production; values are encrypted at rest and reused on redeploys.
    ample deploy . --name --public --env CANARY_SECRET=...
  3. Confirm without echoing
    Expose a route (/config) that reports secret=set or secret=missing, never the value.
  4. Verify
    Fetch the live URL and run the success checks below. On failure read the build log, then the runtime log, fix the cause and deploy again; do not blind-retry.
    ample logs --kind build

Example

Success Checks

Limitations

Cost Estimate

Evidence Summary

Next Actions

  1. Browse the catalog index
    • Method: GET
    • Relative Path: /v1/catalog
  2. Search published recipes by intent, stack and constraints
    • Method: POST
    • Relative Path: /v1/catalog/search
    • Parameters:
      • Body: {"limit":5,"query":"Configure environment and secrets for Astro"}
  3. Prepare a side-effect-free deployment plan for an authorized project
    • Method: POST
    • Relative Path: /v1/catalog/plan
    • Parameters:
      • Body: {"inputs":{},"projectId":"","recipeId":"page:guides:astro:configuration-secrets","recipeRevision":"r1"}
  4. Read the existing agent authentication setup
    • Method: GET
    • Relative Path: /mcp/setup
  5. Browse Astro
    • Method: GET
    • Relative Path: /v1/catalog/nodes/stack%3Aframework-astro
  6. Browse Configure deployment
    • Method: GET
    • Relative Path: /v1/catalog/nodes/intent%3Aconfigure-deployment
  7. Browse Public web service
    • Method: GET
    • Relative Path: /v1/catalog/nodes/pattern%3Apublic-web-service