The controller reads its credentials from files; every other env-file secret says why
ADR 0086. mesh-controller mounts its six own secrets and names them with _FILE twins, so no credential of its own reaches its environment. The 35 containers that still read a secret through an env-file carry secrets-in-environment with the reason; converting each where its software accepts a path is the per-module work of issue 041.
This commit is contained in:
+20
-10
@@ -217,7 +217,8 @@
|
||||
"env-file": [
|
||||
"/var/lib/mailu/mailu.env",
|
||||
"/var/lib/mailu/secret.env"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "redis",
|
||||
@@ -244,7 +245,8 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/data:/data",
|
||||
"/services/mailu/data/dkim:/dkim"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "imap",
|
||||
@@ -259,7 +261,8 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/mail:/mail",
|
||||
"/services/mailu/data/overrides/dovecot:/overrides:ro"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "smtp",
|
||||
@@ -274,7 +277,8 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/mailqueue:/queue",
|
||||
"/services/mailu/data/overrides/postfix:/overrides:ro"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "antispam",
|
||||
@@ -289,7 +293,8 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/filter:/var/lib/rspamd",
|
||||
"/services/mailu/data/overrides/rspamd:/etc/rspamd/override.d:ro"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "antivirus",
|
||||
@@ -303,7 +308,8 @@
|
||||
],
|
||||
"volumes": [
|
||||
"/services/mailu/data/filter:/data"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "webmail",
|
||||
@@ -318,7 +324,8 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/webmail:/data",
|
||||
"/services/mailu/data/overrides/roundcube:/overrides:ro"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "webdav",
|
||||
@@ -332,7 +339,8 @@
|
||||
],
|
||||
"volumes": [
|
||||
"/services/mailu/data/dav:/data"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "fetchmail",
|
||||
@@ -346,7 +354,8 @@
|
||||
],
|
||||
"volumes": [
|
||||
"/services/mailu/data/data/fetchmail:/data"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "front",
|
||||
@@ -368,7 +377,8 @@
|
||||
"volumes": [
|
||||
"/services/mailu/data/certs:/certs",
|
||||
"/services/mailu/data/overrides/nginx:/overrides:ro"
|
||||
]
|
||||
],
|
||||
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
|
||||
Reference in New Issue
Block a user