page:guides:axum:configuration secrets

Configure Environment and Secrets for Axum

Summary

Configuration and secrets for an Axum app on Ample. Verified on Axum: an --env value delivered encrypted and reported as present without being echoed (secret=set). Build and start: cargo build --release in the Rust builder image (stable toolchain, Cargo.lock committed, pure-Rust dependencies), then the release binary on the ubuntu-24.04 template reading PORT and DATABASE_URL.

Requirements

Prerequisites

Workflow Steps

  1. Build and Start
    cargo build --release in the Rust builder image (stable toolchain, Cargo.lock committed, pure-Rust dependencies), then the release binary on the ubuntu-24.04 template reading PORT and DATABASE_URL; the server must bind 0.0.0.0 on PORT.

  2. Pass Values on Deploy
    Use --env KEY=value (repeatable) or --env-file; values are encrypted at rest and reused on redeploys. Declare names only in ample.toml.
    Command: ample deploy . --name --public --env MY_SECRET=...

  3. Verify
    Fetch the live URL and /p/configuration-secrets on the example; on failure, read the build and runtime logs.
    Command: ample logs --kind build

Examples

Success Checks

  1. App responds on its public URL
    Kind: http_get
    Path: /
    Expect: ample canary axum patterns

  2. Configuration-secrets check from the example
    Kind: http_get
    Path: /p/configuration-secrets
    Expect: see the pattern fixture checks

Limitations

Cost Estimate

Always-on monthly price of the tested sizes; apps auto-pause when idle. Buckets are allocation-priced per quota and not included.

Evidence Summary

Last Verified At

Input Schema

Formats