page:guides:nestjs:configuration secrets
Configure environment and secrets for NestJS
Summary
Configuration and secrets for a NestJS app on Ample. Verified on NestJS: an --env value delivered encrypted and reported as present without being echoed (secret=set). Build and start: npm install, nest build (TypeScript) then node dist/main.js on the node-22 template.
Prerequisites
- A NestJS project (npm install, nest build (TypeScript) then node dist/main.js on the node-22 template)
- An Ample account token with servers:write
Workflow Steps
Build and start
npm install, nest build (TypeScript) then node dist/main.js on the node-22 template; the server must bind 0.0.0.0 on PORT.Pass values on deploy
Use --env KEY=value (repeatable) or --env-file; values are encrypted at rest and reused on redeploys. Declare names only in ample.toml.
Command:ample deploy . --name --public --env MY_SECRET=...Verify
Fetch the live URL and /p/configuration-secrets on the example; on failure read the build and runtime logs.
Command:ample logs --kind build
Success Checks
App responds on its public URL
Kind:http_get
Path:/
Expect:ample canary nestjs patternsConfiguration-secrets check from the example
Kind:http_get
Path:/p/configuration-secrets
Expect:see the pattern fixture checks
Limitations
- Verified on the node-22 template at s-1vcpu-1gb; other sizes and NestJS major versions are not verified.
- Region, compliance attestations and request-duration limits are unknown and not claimed.
Cost Estimate
- Currency: USD
- Monthly Amount: 5.0
- Authoritative: true
- Basis: size prices from pricing.toml (loaded by the API) at build revision 1ac5595375130d45290090e82ed0f554ccd45405-dirty
- Note: Always-on monthly price of the tested sizes; apps auto-pause when idle. Buckets are allocation-priced per quota and not included.
Evidence Summary
- Kind:
canary_run - Summary: NestJS pattern fixture deployed on Ample (npm install, nest build (TypeScript) then node dist/main.js on the node-22 template); for this guide: an --env value delivered encrypted and reported as present without being echoed (secret=set).
- Observed At:
2026-09-21T02:34:39Z - Expires At:
2027-03-20T02:34:39Z
Tested Configuration
- Template: node-22
- Runtime: node
- Size: s-1vcpu-1gb
- Install:
npm install - Build:
npm run build --if-present - Start:
npm run start
Input Schema
{
"additionalProperties": false,
"properties": {
"env": {
"description": "Encrypted environment variables",
"items": {
"pattern": "^[A-Z][A-Z0-9_]*=.*$",
"type": "string"
},
"maxItems": 50,
"type": "array"
},
"name": {
"description": "App name",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9-]+$",
"type": "string"
},
"path": {
"description": "Project directory or ample.toml service",
"maxLength": 512,
"minLength": 1,
"type": "string"
},
"release_command": {
"description": "Migration command run before activation",
"maxLength": 512,
"type": "string"
}
},
"required": ["env", "name", "path"],
"type": "object"
}
Examples
- NestJS pattern fixture
- Description: Verified configuration and secrets on NestJS.
- Source Ref:
tests/deploy-canaries/nestjs-patterns