configuration secrets.md

Configure environment and secrets for Phoenix

Summary

Configuration and secrets for a Phoenix app on Ample. Verified on Phoenix: an --env value delivered encrypted and reported as present without being echoed (secret=set). Build and start: mix deps.get, MIX_ENV=prod mix compile and mix release in the builder, then the release bin script with PHX_SERVER=true on the elixir-1.18 template; PORT, DATABASE_URL and SECRET_KEY_BASE read in config/runtime.exs.

Infrastructure requirements

Prerequisites

Exact tested configuration

Steps

  1. Build and start. mix deps.get, MIX_ENV=prod mix compile and mix release in the builder, then the release bin script with PHX_SERVER=true on the elixir-1.18 template; PORT, DATABASE_URL and SECRET_KEY_BASE read in config/runtime.exs; the server must bind 0.0.0.0 on PORT.
  2. Pass values on deploy. Use --env KEY=value (repeatable) or --env-file; values are encrypted at rest and reused on redeploys. Declare names only in ample.toml.
    ample deploy . --name <app-name> --public --env MY_SECRET=...
    ```
3. **Verify.** Fetch the live URL and /p/configuration-secrets on the example; on failure read the build and runtime logs.
ample logs <deployment_id> --kind build
```

Tested examples

Success checks

Limitations

Cost estimate

Estimated 5.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Always-on monthly price of the tested sizes; apps auto-pause when idle. Buckets are allocation-priced per quota and not included.

Verification evidence