The controller reads its credentials from files; every other env-file secret says why

ADR 0086. mesh-controller mounts its six own secrets and names them with
_FILE twins, so no credential of its own reaches its environment. The 35
containers that still read a secret through an env-file carry
secrets-in-environment with the reason; converting each where its software
accepts a path is the per-module work of issue 041.
This commit is contained in:
2026-09-21 10:10:33 +02:00
parent d03520f4ed
commit 32dec5f0c2
25 changed files with 84 additions and 47 deletions
+4 -2
View File
@@ -66,7 +66,8 @@
],
"ports": [
"8283"
]
],
"secrets-in-environment": "the runtime reads its settings from the environment; converting is the per-module work of issue 041"
},
{
"id": "runtime-config",
@@ -103,7 +104,8 @@
"restart-on": [
"runtime-config"
],
"artifact": "runtime"
"artifact": "runtime",
"secrets-in-environment": "the runtime reads its settings from the environment; converting is the per-module work of issue 041"
}
],
"build": {