configuration secrets.md

Configure environment and secrets for FastAPI

Summary

Configure environment variables and secrets for a FastAPI app on Ample. Values passed with --env or --env-file are stored encrypted and injected at runtime; the platform never prints them and ample.toml declares only variable names. The fixture proves delivery by reporting whether the secret is set without echoing it.

Infrastructure requirements

Prerequisites

Exact tested configuration

Steps

  1. Declare, do not commit. In ample.toml declare SMTP_KEY = { secret = true } style entries; never put literal secrets in the manifest.
  2. Pass values on deploy. Use --env KEY=value (repeatable) or --env-file .env.production; values are encrypted at rest and reused on redeploys.
   ample deploy . --name <app-name> --public --start "python3 run.py" --env CANARY_SECRET=...
  1. Confirm without echoing. Expose a route (/config) that reports secret=set or secret=missing, never the value.
  2. Verify. Fetch the live URL and run the success checks below. On failure read the build log, then the runtime log, fix the cause and deploy again; do not blind-retry.
   ample logs <deployment_id> --kind build

Tested examples

Success checks

Limitations

Cost estimate

Estimated 5.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Apps and managed databases auto-pause when idle; the estimate is the always-on monthly price of the tested sizes. Plan quotas and budgets apply.

Verification evidence

Last verified: 2026-09-20T01:42:25Z

Execution binding

MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-20T01:55:48.667900+00:00 at revision 199ff1dfd526, binding state current, required scopes: servers:write.