page:guides:nestjs:configuration secrets

Configure environment and secrets for NestJS

Summary

Configuration and secrets for a NestJS app on Ample. Verified on NestJS: an --env value delivered encrypted and reported as present without being echoed (secret=set). Build and start: npm install, nest build (TypeScript) then node dist/main.js on the node-22 template.

Prerequisites

Workflow Steps

  1. Build and start
    npm install, nest build (TypeScript) then node dist/main.js on the node-22 template; the server must bind 0.0.0.0 on PORT.

  2. Pass values on deploy
    Use --env KEY=value (repeatable) or --env-file; values are encrypted at rest and reused on redeploys. Declare names only in ample.toml.
    Command: ample deploy . --name --public --env MY_SECRET=...

  3. Verify
    Fetch the live URL and /p/configuration-secrets on the example; on failure read the build and runtime logs.
    Command: ample logs --kind build

Success Checks

Limitations

Cost Estimate

Evidence Summary

Tested Configuration

Input Schema

{
  "additionalProperties": false,
  "properties": {
      "env": {
          "description": "Encrypted environment variables",
          "items": {
              "pattern": "^[A-Z][A-Z0-9_]*=.*$",
              "type": "string"
          },
          "maxItems": 50,
          "type": "array"
      },
      "name": {
          "description": "App name",
          "maxLength": 63,
          "minLength": 1,
          "pattern": "^[a-z0-9-]+$",
          "type": "string"
      },
      "path": {
          "description": "Project directory or ample.toml service",
          "maxLength": 512,
          "minLength": 1,
          "type": "string"
      },
      "release_command": {
          "description": "Migration command run before activation",
          "maxLength": 512,
          "type": "string"
      }
  },
  "required": ["env", "name", "path"],
  "type": "object"
}

Examples