The controller reads its credentials from files; every other env-file secret says why

ADR 0086. mesh-controller mounts its six own secrets and names them with
_FILE twins, so no credential of its own reaches its environment. The 35
containers that still read a secret through an env-file carry
secrets-in-environment with the reason; converting each where its software
accepts a path is the per-module work of issue 041.
This commit is contained in:
2026-09-21 10:10:33 +02:00
parent d03520f4ed
commit 32dec5f0c2
25 changed files with 84 additions and 47 deletions
+2 -1
View File
@@ -49,7 +49,8 @@
], ],
"restart-on": [ "restart-on": [
"app-env" "app-env"
] ],
"secrets-in-environment": "the runtime reads its SMTP and AMQP settings from the environment; a file twin in the SDK is the per-module work of issue 041"
} }
] ]
} }
+2 -1
View File
@@ -60,7 +60,8 @@
"restart-on": [ "restart-on": [
"amqp-env" "amqp-env"
], ],
"artifact": "runtime" "artifact": "runtime",
"secrets-in-environment": "the runtime reads MESH_AMQP_* from the environment; a file twin in the SDK is the per-module work of issue 041"
} }
], ],
"build": { "build": {
+2 -1
View File
@@ -85,7 +85,8 @@
], ],
"volumes": [ "volumes": [
"/services/baserow/data:/baserow/data" "/services/baserow/data:/baserow/data"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
+2 -1
View File
@@ -59,7 +59,8 @@
], ],
"ports": [ "ports": [
"35621:35621" "35621:35621"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
} }
] ]
} }
+4 -2
View File
@@ -113,7 +113,8 @@
], ],
"volumes": [ "volumes": [
"/services/gitea/gitea:/data" "/services/gitea/gitea:/data"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "admin-bootstrap", "id": "admin-bootstrap",
@@ -137,7 +138,8 @@
"/bin/sh", "/bin/sh",
"-c", "-c",
"su-exec git gitea admin user create --admin --username \"$MESH_GITEA_ADMIN_USER\" --email mesh-admin@localhost --password \"$(cat /run/secrets/admin)\" --must-change-password=false || true" "su-exec git gitea admin user create --admin --username \"$MESH_GITEA_ADMIN_USER\" --email mesh-admin@localhost --password \"$(cat /run/secrets/admin)\" --must-change-password=false || true"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
+2 -1
View File
@@ -59,7 +59,8 @@
], ],
"volumes": [ "volumes": [
"/services/grafana/data:/var/lib/grafana" "/services/grafana/data:/var/lib/grafana"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
+2 -1
View File
@@ -52,7 +52,8 @@
], ],
"ports": [ "ports": [
"8000" "8000"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
+2 -1
View File
@@ -65,7 +65,8 @@
"volumes": [ "volumes": [
"/services/influxdb/data:/var/lib/influxdb2", "/services/influxdb/data:/var/lib/influxdb2",
"/services/influxdb/config:/etc/influxdb2" "/services/influxdb/config:/etc/influxdb2"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
+2 -1
View File
@@ -99,7 +99,8 @@
], ],
"ports": [ "ports": [
"9000" "9000"
] ],
"secrets-in-environment": "the API reads its settings from the environment; converting is the per-module work of issue 041"
} }
] ]
} }
+2 -1
View File
@@ -96,7 +96,8 @@
], ],
"ports": [ "ports": [
"8080" "8080"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
+4 -2
View File
@@ -66,7 +66,8 @@
], ],
"ports": [ "ports": [
"8283" "8283"
] ],
"secrets-in-environment": "the runtime reads its settings from the environment; converting is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
@@ -103,7 +104,8 @@
"restart-on": [ "restart-on": [
"runtime-config" "runtime-config"
], ],
"artifact": "runtime" "artifact": "runtime",
"secrets-in-environment": "the runtime reads its settings from the environment; converting is the per-module work of issue 041"
} }
], ],
"build": { "build": {
+20 -10
View File
@@ -217,7 +217,8 @@
"env-file": [ "env-file": [
"/var/lib/mailu/mailu.env", "/var/lib/mailu/mailu.env",
"/var/lib/mailu/secret.env" "/var/lib/mailu/secret.env"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "redis", "id": "redis",
@@ -244,7 +245,8 @@
"volumes": [ "volumes": [
"/services/mailu/data/data:/data", "/services/mailu/data/data:/data",
"/services/mailu/data/dkim:/dkim" "/services/mailu/data/dkim:/dkim"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "imap", "id": "imap",
@@ -259,7 +261,8 @@
"volumes": [ "volumes": [
"/services/mailu/data/mail:/mail", "/services/mailu/data/mail:/mail",
"/services/mailu/data/overrides/dovecot:/overrides:ro" "/services/mailu/data/overrides/dovecot:/overrides:ro"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "smtp", "id": "smtp",
@@ -274,7 +277,8 @@
"volumes": [ "volumes": [
"/services/mailu/data/mailqueue:/queue", "/services/mailu/data/mailqueue:/queue",
"/services/mailu/data/overrides/postfix:/overrides:ro" "/services/mailu/data/overrides/postfix:/overrides:ro"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "antispam", "id": "antispam",
@@ -289,7 +293,8 @@
"volumes": [ "volumes": [
"/services/mailu/data/filter:/var/lib/rspamd", "/services/mailu/data/filter:/var/lib/rspamd",
"/services/mailu/data/overrides/rspamd:/etc/rspamd/override.d:ro" "/services/mailu/data/overrides/rspamd:/etc/rspamd/override.d:ro"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "antivirus", "id": "antivirus",
@@ -303,7 +308,8 @@
], ],
"volumes": [ "volumes": [
"/services/mailu/data/filter:/data" "/services/mailu/data/filter:/data"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "webmail", "id": "webmail",
@@ -318,7 +324,8 @@
"volumes": [ "volumes": [
"/services/mailu/data/webmail:/data", "/services/mailu/data/webmail:/data",
"/services/mailu/data/overrides/roundcube:/overrides:ro" "/services/mailu/data/overrides/roundcube:/overrides:ro"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "webdav", "id": "webdav",
@@ -332,7 +339,8 @@
], ],
"volumes": [ "volumes": [
"/services/mailu/data/dav:/data" "/services/mailu/data/dav:/data"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "fetchmail", "id": "fetchmail",
@@ -346,7 +354,8 @@
], ],
"volumes": [ "volumes": [
"/services/mailu/data/data/fetchmail:/data" "/services/mailu/data/data/fetchmail:/data"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "front", "id": "front",
@@ -368,7 +377,8 @@
"volumes": [ "volumes": [
"/services/mailu/data/certs:/certs", "/services/mailu/data/certs:/certs",
"/services/mailu/data/overrides/nginx:/overrides:ro" "/services/mailu/data/overrides/nginx:/overrides:ro"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
+2 -1
View File
@@ -74,7 +74,8 @@
"artifact": "runtime", "artifact": "runtime",
"restart-on": [ "restart-on": [
"db-env" "db-env"
] ],
"secrets-in-environment": "the mesh's own runtime reads MESH_STORE_* from the environment; a file twin in the SDK is the per-module work of issue 041"
} }
], ],
"build": { "build": {
+14 -12
View File
@@ -26,13 +26,6 @@
"path": "/var/lib/mesh/mesh-controller", "path": "/var/lib/mesh/mesh-controller",
"mode": "0700" "mode": "0700"
}, },
{
"id": "control-env",
"type": "file",
"path": "/var/lib/mesh/mesh-controller/control.env",
"mode": "0600",
"content": "MESH_STORE_INVENTORY=${secret:inventory}\nMESH_STORE_IDENTITY=${secret:identity}\nMESH_STORE_LICENCES=${secret:licences}\nMESH_BROKER_AMQP=${secret:broker}\nMESH_BROKER_MANAGEMENT=${secret:broker-management}\nMESH_BROKER_ADDRESS=${secret:broker-address}\n"
},
{ {
"id": "server", "id": "server",
"type": "container", "type": "container",
@@ -42,14 +35,23 @@
"args": [ "args": [
"serve" "serve"
], ],
"env-file": [
"/var/lib/mesh/mesh-controller/control.env"
],
"env": { "env": {
"MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt" "MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt",
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
"MESH_STORE_IDENTITY_FILE": "/run/secrets/identity",
"MESH_STORE_LICENCES_FILE": "/run/secrets/licences",
"MESH_BROKER_AMQP_FILE": "/run/secrets/broker",
"MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management",
"MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address"
}, },
"volumes": [ "volumes": [
"mesh-broker-tls:/broker-tls:ro" "mesh-broker-tls:/broker-tls:ro",
"/var/lib/mesh/mesh-controller/inventory:/run/secrets/inventory:ro",
"/var/lib/mesh/mesh-controller/identity:/run/secrets/identity:ro",
"/var/lib/mesh/mesh-controller/licences:/run/secrets/licences:ro",
"/var/lib/mesh/mesh-controller/broker:/run/secrets/broker:ro",
"/var/lib/mesh/mesh-controller/broker-management:/run/secrets/broker-management:ro",
"/var/lib/mesh/mesh-controller/broker-address:/run/secrets/broker-address:ro"
], ],
"restart-on": [ "restart-on": [
"control-env" "control-env"
+2 -1
View File
@@ -96,7 +96,8 @@
], ],
"volumes": [ "volumes": [
"/services/minio/data/data1-1:/data" "/services/minio/data/data1-1:/data"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime", "id": "runtime",
+2 -1
View File
@@ -60,7 +60,8 @@
}, },
"env-file": [ "env-file": [
"/var/lib/model-usage/db.env" "/var/lib/model-usage/db.env"
] ],
"secrets-in-environment": "the mesh's own runtime reads MESH_STORE_* from the environment; a file twin in the SDK is the per-module work of issue 041"
} }
] ]
} }
+2 -1
View File
@@ -95,7 +95,8 @@
], ],
"volumes": [ "volumes": [
"/services/mongodb/db-data:/data/db" "/services/mongodb/db-data:/data/db"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime", "id": "runtime",
+2 -1
View File
@@ -91,7 +91,8 @@
], ],
"volumes": [ "volumes": [
"/services/mssql/db-data:/var/opt/mssql" "/services/mssql/db-data:/var/opt/mssql"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime", "id": "runtime",
+2 -1
View File
@@ -78,7 +78,8 @@
], ],
"volumes": [ "volumes": [
"/services/n8n/n8n-data:/home/node/.n8n" "/services/n8n/n8n-data:/home/node/.n8n"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
} }
] ]
} }
+2 -1
View File
@@ -87,7 +87,8 @@
], ],
"volumes": [ "volumes": [
"/services/nextcloud/html:/var/www/html" "/services/nextcloud/html:/var/www/html"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
+2 -1
View File
@@ -109,7 +109,8 @@
"/services/only-office/rabbitmq:/var/lib/rabbitmq", "/services/only-office/rabbitmq:/var/lib/rabbitmq",
"/services/only-office/redis:/var/lib/redis", "/services/only-office/redis:/var/lib/redis",
"/services/only-office/fonts:/usr/share/fonts/truetype/custom" "/services/only-office/fonts:/usr/share/fonts/truetype/custom"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
} }
] ]
} }
+2 -1
View File
@@ -74,7 +74,8 @@
], ],
"ports": [ "ports": [
"9000" "9000"
] ],
"secrets-in-environment": "the server reads its settings from the environment; converting is the per-module work of issue 041"
}, },
{ {
"id": "admin-client", "id": "admin-client",
+2 -1
View File
@@ -70,7 +70,8 @@
], ],
"ports": [ "ports": [
"8080" "8080"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
+2 -1
View File
@@ -103,7 +103,8 @@
"volumes": [ "volumes": [
"/var/lib/step-ca:/home/step", "/var/lib/step-ca:/home/step",
"/var/lib/mesh/step-ca:/run/mesh:ro" "/var/lib/mesh/step-ca:/run/mesh:ro"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
} }
] ]
} }
+2 -1
View File
@@ -101,7 +101,8 @@
], ],
"ports": [ "ports": [
"3000" "3000"
] ],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}, },
{ {
"id": "runtime", "id": "runtime",