Six modules take their secrets from files; the rest say precisely why not

From the survey of every env-file secret (ADR 0086, issue 041): amqp-ping,
minio, mongodb and grafana use the _FILE twin their software honours;
mesh-catalog and model-usage read DATABASE_URL_FILE (a file the mesh
templates, mounted where only the runtime reads it); grafana's secret files
belong to its own account. Two dead deliveries removed: a line nothing read
in amqp-email-forwarder, and mailu's secret.env on four containers that
never read it. The 25 exceptions that remain carry the surveyed reason —
convertible and awaiting a bed, convertible through a generated config file,
the application's own code, or not convertible.
This commit is contained in:
2026-09-21 12:29:25 +02:00
parent db597bcb71
commit 1a28e5aec6
26 changed files with 106 additions and 96 deletions
+14 -22
View File
@@ -218,7 +218,7 @@
"/var/lib/mailu/mailu.env",
"/var/lib/mailu/secret.env"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
},
{
"id": "redis",
@@ -246,7 +246,7 @@
"/services/mailu/data/data:/data",
"/services/mailu/data/dkim:/dkim"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
},
{
"id": "imap",
@@ -255,14 +255,12 @@
"image": "ghcr.io/mailu/dovecot@sha256:46d18ba51032be8ebd6841aa49c1ef8762c729038c5fd86a081b5b884d478af9",
"network": "mailu",
"env-file": [
"/var/lib/mailu/mailu.env",
"/var/lib/mailu/secret.env"
"/var/lib/mailu/mailu.env"
],
"volumes": [
"/services/mailu/data/mail:/mail",
"/services/mailu/data/overrides/dovecot:/overrides:ro"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
]
},
{
"id": "smtp",
@@ -271,14 +269,12 @@
"image": "ghcr.io/mailu/postfix@sha256:bbf882880f68849511710b35237a933f3fe80c4b28bf48ff20205dbd1f1433d7",
"network": "mailu",
"env-file": [
"/var/lib/mailu/mailu.env",
"/var/lib/mailu/secret.env"
"/var/lib/mailu/mailu.env"
],
"volumes": [
"/services/mailu/data/mailqueue:/queue",
"/services/mailu/data/overrides/postfix:/overrides:ro"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
]
},
{
"id": "antispam",
@@ -287,14 +283,12 @@
"image": "ghcr.io/mailu/rspamd@sha256:e87ab93dd252cc69499caa5317dd10d445fd4291a7ecf6bca09793c7d475a0c8",
"network": "mailu",
"env-file": [
"/var/lib/mailu/mailu.env",
"/var/lib/mailu/secret.env"
"/var/lib/mailu/mailu.env"
],
"volumes": [
"/services/mailu/data/filter:/var/lib/rspamd",
"/services/mailu/data/overrides/rspamd:/etc/rspamd/override.d:ro"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
]
},
{
"id": "antivirus",
@@ -309,7 +303,7 @@
"volumes": [
"/services/mailu/data/filter:/data"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
},
{
"id": "webmail",
@@ -325,7 +319,7 @@
"/services/mailu/data/webmail:/data",
"/services/mailu/data/overrides/roundcube:/overrides:ro"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
},
{
"id": "webdav",
@@ -340,7 +334,7 @@
"volumes": [
"/services/mailu/data/dav:/data"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
},
{
"id": "fetchmail",
@@ -355,7 +349,7 @@
"volumes": [
"/services/mailu/data/data/fetchmail:/data"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
},
{
"id": "front",
@@ -364,8 +358,7 @@
"image": "ghcr.io/mailu/nginx@sha256:09f28ab6d36367fcacc7994f7021f132ac845bdc05f04bf80906102d11aaa057",
"network": "mailu",
"env-file": [
"/var/lib/mailu/mailu.env",
"/var/lib/mailu/secret.env"
"/var/lib/mailu/mailu.env"
],
"ports": [
"25",
@@ -377,8 +370,7 @@
"volumes": [
"/services/mailu/data/certs:/certs",
"/services/mailu/data/overrides/nginx:/overrides:ro"
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
]
},
{
"id": "runtime-config",