Skip to main content
Level 1
September 8, 2026
Solved

Adding OSGi Configurations in AMS

  • September 8, 2026
  • 4 replies
  • 323 views

We are looking to manage OSGi configurations in the AMS environment instead of storing sensitive values in the codebase. In Adobe Cloud Manager, there is an option to manage environment-specific secrets and configurations. Is there a similar approach available in AMS, and if so, how can we manage these configurations securely?

    Best answer by Jineet_Vora

    ​@ayetukur - Unfortunately, the Cloud Manager in AMS doesn’t provide you “environment variables” like AEMaaCS Cloud Manager where you can define secrets securely. It only provides “pipeline variables” where you can define secrets but that secret is for build and not for your running AEM instance: https://developer.adobe.com/experience-cloud/cloud-manager/reference/api#operation/getEnvironmentVariables

    Using the traditional Crypto Support in AEM AMS is one option where you encrypt the secret on each environment and then store it in OSGi configs https://experienceleague.adobe.com/en/docs/experience-manager-65/content/security/encryption-support-for-configuration-properties

    Another secure way is to store the secrets in AWS Secrets Manager and if your AMS infra is on AWS as well then you can setup cross account resource policy between the two accounts and you can then request the secret from Adobe hosted EC2 author/publisher. We use something very similar and is an approved/secured way of fetching the secrets in AEM.

    4 replies

    Jineet_Vora
    Adobe Champion and Community Advisor
    Jineet_VoraAdobe Champion and Community AdvisorAccepted solution
    Adobe Champion and Community Advisor
    September 8, 2026

    ​@ayetukur - Unfortunately, the Cloud Manager in AMS doesn’t provide you “environment variables” like AEMaaCS Cloud Manager where you can define secrets securely. It only provides “pipeline variables” where you can define secrets but that secret is for build and not for your running AEM instance: https://developer.adobe.com/experience-cloud/cloud-manager/reference/api#operation/getEnvironmentVariables

    Using the traditional Crypto Support in AEM AMS is one option where you encrypt the secret on each environment and then store it in OSGi configs https://experienceleague.adobe.com/en/docs/experience-manager-65/content/security/encryption-support-for-configuration-properties

    Another secure way is to store the secrets in AWS Secrets Manager and if your AMS infra is on AWS as well then you can setup cross account resource policy between the two accounts and you can then request the secret from Adobe hosted EC2 author/publisher. We use something very similar and is an approved/secured way of fetching the secrets in AEM.

    Magicr
    Level 6
    September 11, 2026

    ​@ayetukur If you want to use the Crypto Support, there is a very important thing you should know: The base of entcrypted Strings in AMS are two files. These can you find under following path: “crx-quickstart/launchpad/felix/xxx/data”. When you have to migrate your instance you need a copy of those for your new instance, else the new instance will decrypt into a wrong result.

    xxx:

    “bundle25” (AEM 6.5 or older)

    “bundle35” (AEM 6.5 lts)

    AMANATH_ULLAH
    Community Advisor
    Community Advisor
    September 10, 2026

    ​@ayetukur 
    There is no such option in AMS, however you can use crypto support in AEM 
    You can also use other options such as Azure Key Vault, AWS Secrets Manager, HashiCorp Vault

    Amanath Ullah
    Raja_Reddy
    Community Advisor
    Community Advisor
    September 10, 2026

    Hi ​@ayetukur 
    AMS does not provide an equivalent to Cloud Manager Environment Variables/Secrets available in AEM as a Cloud Service. Typically, OSGi configurations are deployed as part of the code package, while sensitive values should be managed using AEM's encrypted configuration properties or maintained directly at the environment level by AMS administrators. For enterprise use cases, integrating with an external secrets management solution such as Azure Key Vault or HashiCorp Vault is also a common approach to avoid storing secrets in source control.
    https://experienceleague.adobe.com/en/docs/experience-manager-cloud-service/content/implementing/deploying/configuring-osgi