page:guides:django:configuration secrets

Configure Environment and Secrets for Django

Summary

Configure environment variables and secrets for a Django app on Ample. Values passed with --env or --env-file are stored encrypted and injected at runtime; the platform never prints them and ample.toml declares only variable names. The fixture proves delivery by reporting whether the secret is set without echoing it.

Prerequisites

Tested Configuration

Input Schema

Workflow Steps

  1. Declare, do not commit: In ample.toml declare SMTP_KEY = { secret = true } style entries; never put literal secrets in the manifest.
  2. Pass values on deploy: Use --env KEY=value (repeatable) or --env-file .env.production; values are encrypted at rest and reused on redeploys.
  3. Confirm without echoing: Expose a route (/config) that reports secret=set or secret=missing, never the value.
  4. Verify: Fetch the live URL and run the success checks below. On failure read the build log, then the runtime log, fix the cause and deploy again; do not blind-retry.

Examples

Success Checks

Limitations

Cost Estimate

Next Actions