Spring Boot
Article 18: External Configuration & Secrets Management
By Utility Zone · 2026-01-27T18:28:09.006928
1. Introduction
Hardcoding configuration works only until:
- You deploy to another environment
- Secrets get exposed
- You need environment-specific behavior
Real-world Spring Boot applications must read configuration from outside the codebase.
This article shows how to handle external configuration and secrets safely.
2. Why External Configuration Matters
Problems with hardcoded values:
- Code changes for config changes
- Secrets committed to Git
- Difficult deployments
External configuration allows:
✔ Same artifact across environments
✔ Secure secret handling
✔ Easy CI/CD integration
3. Configuration Priority in Spring Boot
Spring Boot reads configuration in this order (high → low priority):
- Command-line arguments
- Environment variables
- External
application.properties - Packaged
application.properties
This gives you full flexibility.
4. Using Environment Variables
4.1 Defining Environment Variables
Linux / Mac:
export DB_URL=jdbc:mysql://localhost:3306/app
Windows (PowerShell):
setx DB_URL "jdbc:mysql://localhost:3306/app"
4.2 Reading Environment Variables
spring.datasource.url=${DB_URL}
spring.datasource.username=${DB_USER}
spring.datasource.password=${DB_PASSWORD}
Spring Boot resolves them automatically.
5. Default Values for Safety
server.port=${SERVER_PORT:8080}
If SERVER_PORT is not set, Spring uses 8080.
6. External application.properties File
You can place config outside the JAR.
Example:
java -jar app.jar --spring.config.location=/config/application.properties
Useful for:
- Docker
- Cloud deployments
7. Secrets Management Best Practices
❌ Never commit secrets to Git
❌ Never log secrets
❌ Never hardcode passwords
✔ Use environment variables
✔ Use secret managers
✔ Rotate secrets periodically
8. Using .env Files (Local Development)
For local development only:
DB_USER=root
DB_PASSWORD=secret
Load using tools like:
- IDE env support
- Docker compose
Do NOT commit .env files.
9. Spring Profiles + External Config
Combine profiles with env vars:
spring.profiles.active=${SPRING_PROFILE:dev}
This enables:
- Dev config locally
- Prod config in cloud
10. Docker & Secrets (Preview)
Docker example:
environment:
- DB_USER=admin
- DB_PASSWORD=securepass
Cloud platforms inject secrets similarly.
11. Common Mistakes
❌ Checking secrets into repo
❌ Using same secrets everywhere
❌ Printing env vars in logs
❌ Forgetting defaults
12. What You Should Understand Before Moving On
You should now know:
- How Spring Boot reads external config
- How to use environment variables
- How to handle secrets safely
- Why external config is mandatory
13. What’s Next?
➡ Article 19: Dockerizing Spring Boot Applications
- Dockerfile
- Containerizing your app
- Running Spring Boot in Docker
Type Next when you’re ready.