page:guides:fastapi:configuration secrets
Configure environment and secrets for FastAPI
Configure environment variables and secrets for a FastAPI app on Ample. Values passed with --env or --env-file are stored encrypted and injected at runtime; the platform never prints them and ample.toml declares only variable names. The fixture proves delivery by reporting whether the secret is set without echoing it.
Prerequisites
- Code that reads configuration from the process environment
- The secret values at hand for
--envor an env file - An Ample account token with
servers:write
Tested Configuration
- Template: python-3.12
- Runtime: python
- Size: s-1vcpu-1gb
- Install:
python3 -m pip install --target .ample/python -r requirements.txt - Start:
PYTHONPATH=.ample/python:${PYTHONPATH:-} python3 run.py
Workflow Steps
Declare, do not commit
In ample.toml declareSMTP_KEY = { secret = true }style entries; never put literal secrets in the manifest.Pass values on deploy
Use--env KEY=value(repeatable) or--env-file .env.production; values are encrypted at rest and reused on redeploys.
Command:ample deploy . --name --public --start "python3 run.py" --env CANARY_SECRET=...Confirm without echoing
Expose a route (/config) that reportssecret=setorsecret=missing, never the value.Verify
Fetch the live URL and run the success checks below. On failure read the build log, then the runtime log, fix the cause and deploy again; do not blind-retry.
Command:ample logs --kind build
Examples
- FastAPI secret probe canary
/config reports secret=set for an --env value delivered encrypted.
Source Reference:tests/deploy-canaries/fastapi-postgres-api
Success Checks
- App sees the configured variable without exposing it
- Kind:
http_get - Path:
/config - Expect:
secret=set
- Kind:
Limitations
- Verified on the
node-22template ats-1vcpu-1gb; other templates and sizes are not verified by this recipe. - Region, compliance attestations and request-duration limits are unknown and not claimed.
- Apps auto-pause when idle and wake on the next request; always-on is an operator setting, not a plan feature.
- Plain env in the API request is rejected; only the encrypted path is supported.
- Rotating a secret requires a redeploy with the new value.
Cost Estimate
- Currency: USD
- Monthly Amount: 5.0
- Basis: size prices from
pricing.toml(loaded by the API) at build revision1ac5595375130d45290090e82ed0f554ccd45405-dirty - Components:
- Name: app server
- Size:
s-1vcpu-1gb - Quantity: 1.0
- Monthly Amount: 5.0
- Size:
- Name: app server
- Note: Apps and managed databases auto-pause when idle; the estimate is the always-on monthly price of the tested sizes. Plan quotas and budgets apply.
Evidence Summary
- Kind: canary_run
- Summary: FastAPI REST API using psycopg with no
DATABASE_URLsupplied: Ample auto-provisioned a managed PostgreSQL 16 database and/itemsreportedpostgres=okafter a real insert and count. - Observed At:
2026-09-20T01:42:25Z - Implementation Revision:
199ff1dfd52683832ae75d3f98b53a7a4bff7f96-dirty (CLI e3181f5) - Expires At:
2027-03-19T01:42:25Z - Scope:
- CLI Version:
0.1.20 - Platform:
hosted-beta - Template:
node-22
- CLI Version:
- Summary: FastAPI REST API using psycopg with no
Next Actions
- Browse the catalog index
- On clicking this, it will navigate to browse the catalog index.
- Search published recipes by intent, stack and constraints
- Search for the recipes in the catalog.
- Prepare a side-effect-free deployment plan for an authorized project
- Prepare a deployment plan.
- Read the existing agent authentication setup
- Check the agent authentication setup.
- Browse FastAPI
- Browse the FastAPI catalog.
- Browse Configure deployment
- Check out the deployment configuration options.
- Browse Public web service
- Look into the public web service options.