Six modules take their secrets from files; the rest say precisely why not
From the survey of every env-file secret (ADR 0086, issue 041): amqp-ping, minio, mongodb and grafana use the _FILE twin their software honours; mesh-catalog and model-usage read DATABASE_URL_FILE (a file the mesh templates, mounted where only the runtime reads it); grafana's secret files belong to its own account. Two dead deliveries removed: a line nothing read in amqp-email-forwarder, and mailu's secret.env on four containers that never read it. The 25 exceptions that remain carry the surveyed reason — convertible and awaiting a bed, convertible through a generated config file, the application's own code, or not convertible.
This commit is contained in:
+14
-22
@@ -218,7 +218,7 @@
|
||||
"/var/lib/mailu/mailu.env",
|
||||
"/var/lib/mailu/secret.env"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
|
||||
},
|
||||
{
|
||||
"id": "redis",
|
||||
@@ -246,7 +246,7 @@
|
||||
"/services/mailu/data/data:/data",
|
||||
"/services/mailu/data/dkim:/dkim"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
|
||||
},
|
||||
{
|
||||
"id": "imap",
|
||||
@@ -255,14 +255,12 @@
|
||||
"image": "ghcr.io/mailu/dovecot@sha256:46d18ba51032be8ebd6841aa49c1ef8762c729038c5fd86a081b5b884d478af9",
|
||||
"network": "mailu",
|
||||
"env-file": [
|
||||
"/var/lib/mailu/mailu.env",
|
||||
"/var/lib/mailu/secret.env"
|
||||
"/var/lib/mailu/mailu.env"
|
||||
],
|
||||
"volumes": [
|
||||
"/services/mailu/data/mail:/mail",
|
||||
"/services/mailu/data/overrides/dovecot:/overrides:ro"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "smtp",
|
||||
@@ -271,14 +269,12 @@
|
||||
"image": "ghcr.io/mailu/postfix@sha256:bbf882880f68849511710b35237a933f3fe80c4b28bf48ff20205dbd1f1433d7",
|
||||
"network": "mailu",
|
||||
"env-file": [
|
||||
"/var/lib/mailu/mailu.env",
|
||||
"/var/lib/mailu/secret.env"
|
||||
"/var/lib/mailu/mailu.env"
|
||||
],
|
||||
"volumes": [
|
||||
"/services/mailu/data/mailqueue:/queue",
|
||||
"/services/mailu/data/overrides/postfix:/overrides:ro"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "antispam",
|
||||
@@ -287,14 +283,12 @@
|
||||
"image": "ghcr.io/mailu/rspamd@sha256:e87ab93dd252cc69499caa5317dd10d445fd4291a7ecf6bca09793c7d475a0c8",
|
||||
"network": "mailu",
|
||||
"env-file": [
|
||||
"/var/lib/mailu/mailu.env",
|
||||
"/var/lib/mailu/secret.env"
|
||||
"/var/lib/mailu/mailu.env"
|
||||
],
|
||||
"volumes": [
|
||||
"/services/mailu/data/filter:/var/lib/rspamd",
|
||||
"/services/mailu/data/overrides/rspamd:/etc/rspamd/override.d:ro"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "antivirus",
|
||||
@@ -309,7 +303,7 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/filter:/data"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
|
||||
},
|
||||
{
|
||||
"id": "webmail",
|
||||
@@ -325,7 +319,7 @@
|
||||
"/services/mailu/data/webmail:/data",
|
||||
"/services/mailu/data/overrides/roundcube:/overrides:ro"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
|
||||
},
|
||||
{
|
||||
"id": "webdav",
|
||||
@@ -340,7 +334,7 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/dav:/data"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
|
||||
},
|
||||
{
|
||||
"id": "fetchmail",
|
||||
@@ -355,7 +349,7 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/data/fetchmail:/data"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
|
||||
},
|
||||
{
|
||||
"id": "front",
|
||||
@@ -364,8 +358,7 @@
|
||||
"image": "ghcr.io/mailu/nginx@sha256:09f28ab6d36367fcacc7994f7021f132ac845bdc05f04bf80906102d11aaa057",
|
||||
"network": "mailu",
|
||||
"env-file": [
|
||||
"/var/lib/mailu/mailu.env",
|
||||
"/var/lib/mailu/secret.env"
|
||||
"/var/lib/mailu/mailu.env"
|
||||
],
|
||||
"ports": [
|
||||
"25",
|
||||
@@ -377,8 +370,7 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/certs:/certs",
|
||||
"/services/mailu/data/overrides/nginx:/overrides:ro"
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
|
||||
Reference in New Issue
Block a user