Spring Boot

Article 18: External Configuration & Secrets Management

By Utility Zone · 2026-01-27T18:28:09.006928

1. Introduction

Hardcoding configuration works only until:

  • You deploy to another environment
  • Secrets get exposed
  • You need environment-specific behavior

Real-world Spring Boot applications must read configuration from outside the codebase.

This article shows how to handle external configuration and secrets safely.


2. Why External Configuration Matters

Problems with hardcoded values:

  • Code changes for config changes
  • Secrets committed to Git
  • Difficult deployments

External configuration allows: ✔ Same artifact across environments
✔ Secure secret handling
✔ Easy CI/CD integration


3. Configuration Priority in Spring Boot

Spring Boot reads configuration in this order (high → low priority):

  1. Command-line arguments
  2. Environment variables
  3. External application.properties
  4. Packaged application.properties

This gives you full flexibility.


4. Using Environment Variables

4.1 Defining Environment Variables

Linux / Mac:

export DB_URL=jdbc:mysql://localhost:3306/app

Windows (PowerShell):

setx DB_URL "jdbc:mysql://localhost:3306/app"

4.2 Reading Environment Variables

spring.datasource.url=${DB_URL}
spring.datasource.username=${DB_USER}
spring.datasource.password=${DB_PASSWORD}

Spring Boot resolves them automatically.


5. Default Values for Safety

server.port=${SERVER_PORT:8080}

If SERVER_PORT is not set, Spring uses 8080.


6. External application.properties File

You can place config outside the JAR.

Example:

java -jar app.jar --spring.config.location=/config/application.properties

Useful for:

  • Docker
  • Cloud deployments

7. Secrets Management Best Practices

❌ Never commit secrets to Git
❌ Never log secrets
❌ Never hardcode passwords

✔ Use environment variables
✔ Use secret managers
✔ Rotate secrets periodically


8. Using .env Files (Local Development)

For local development only:

DB_USER=root
DB_PASSWORD=secret

Load using tools like:

  • IDE env support
  • Docker compose

Do NOT commit .env files.


9. Spring Profiles + External Config

Combine profiles with env vars:

spring.profiles.active=${SPRING_PROFILE:dev}

This enables:

  • Dev config locally
  • Prod config in cloud

10. Docker & Secrets (Preview)

Docker example:

environment:
  - DB_USER=admin
  - DB_PASSWORD=securepass

Cloud platforms inject secrets similarly.


11. Common Mistakes

❌ Checking secrets into repo
❌ Using same secrets everywhere
❌ Printing env vars in logs
❌ Forgetting defaults


12. What You Should Understand Before Moving On

You should now know:

  • How Spring Boot reads external config
  • How to use environment variables
  • How to handle secrets safely
  • Why external config is mandatory

13. What’s Next?

➡ Article 19: Dockerizing Spring Boot Applications

  • Dockerfile
  • Containerizing your app
  • Running Spring Boot in Docker

Type Next when you’re ready.