page:guides:echo:configuration secrets

Configure environment and secrets for Echo

Summary

Configuration and secrets for a Echo app on Ample. Verified on Echo: an --env value delivered encrypted and reported as present without being echoed (secret=set). Build and start: CGO_ENABLED=0 go build -o app ./... then ./app on the ubuntu-24.04 template (go.sum committed for a reproducible build).

Resource Requirements

Prerequisites

Workflow Steps

  1. Build and start: CGO_ENABLED=0 go build -o app ./... then ./app on the ubuntu-24.04 template (go.sum committed for a reproducible build); the server must bind 0.0.0.0 on PORT.

  2. Pass values on deploy: Use --env KEY=value (repeatable) or --env-file; values are encrypted at rest and reused on redeploys. Declare names only in ample.toml.

    Command: ample deploy . --name --public --env MY_SECRET=...

  3. Verify: Fetch the live URL and /p/configuration-secrets on the example; on failure read the build and runtime logs.

    Command: ample logs --kind build

Tested Configuration

Examples

Echo pattern fixture

Description: Verified configuration and secrets on Echo. Source Ref: tests/deploy-canaries/echo-patterns

Success Checks

Limitations

Cost Estimate

Cost Breakdown

Evidence Summary

Next Actions