page:guides:quarkus:configuration secrets

Configure environment and secrets for Quarkus

Summary

Configuration and secrets for a Quarkus app on Ample. Verified on Quarkus: an --env value delivered encrypted and reported as present without being echoed (secret=set). Build and start: ./mvnw -q -DskipTests package producing one uber-jar (quarkus.package.jar.type=uber-jar), then java -jar on the jvm-21 template (Temurin JDK 21) with quarkus.http.port read from PORT.

Representative Queries

Required Resources

Prerequisites

Workflow Steps

  1. Build and start
    ./mvnw -q -DskipTests package producing one uber-jar (quarkus.package.jar.type=uber-jar), then java -jar on the jvm-21 template (Temurin JDK 21) with quarkus.http.port read from PORT; the server must bind 0.0.0.0 on PORT.

  2. Pass values on deploy
    Use --env KEY=value (repeatable) or --env-file; values are encrypted at rest and reused on redeploys. Declare names only in ample.toml.
    Command: ample deploy . --name --public --env MY_SECRET=...

  3. Verify
    Fetch the live URL and /p/configuration-secrets on the example; on failure read the build and runtime logs.
    Command: ample logs --kind build

Tested Configuration

Examples

Success Checks

Limitations

Cost Estimate

Evidence Summary

Next Actions

Formats: