page:guides:next js:configuration secrets

Configure environment and secrets for Next.js

Summary

Configure environment variables and secrets for a Next.js app on Ample. Values passed with --env or --env-file are stored encrypted and injected at runtime; the platform never prints them and ample.toml declares only variable names. The fixture proves delivery by reporting whether the secret is set without echoing it.

Prerequisites

Workflow Steps

  1. Declare, do not commit
    In ample.toml declare SMTP_KEY = { secret = true } style entries; never put literal secrets in the manifest.
  2. Pass values on deploy
    Use --env KEY=value (repeatable) or --env-file .env.production; values are encrypted at rest and reused on redeploys.
    ample deploy . --name  --public --env CANARY_SECRET=...  
    
  3. Confirm without echoing
    Expose a route (/api/config) that reports secret=set or secret=missing, never the value.
  4. Verify
    Fetch the live URL and run the success checks below. On failure read the build log, then the runtime log, fix the cause and deploy again; do not blind-retry.
    ample logs  --kind build  
    

Tested Configuration

Success Checks

Limitations

Cost Estimate