diff --git a/modules/umami/client.ts b/modules/umami/client.ts index 4ef410c..17fea1e 100644 --- a/modules/umami/client.ts +++ b/modules/umami/client.ts @@ -2,6 +2,18 @@ // changes when umami's API does (novox/hq ADR 0039). Both this module's tools and its provisioner // import it; nothing outside umami does. +import { readFileSync } from "node:fs"; + +/** Read a secret from the file the mesh mounted it at, if the pointing env is set. */ +function readSecret(path: string | undefined): string | undefined { + if (!path) return undefined; + try { + return readFileSync(path, "utf8").trim() || undefined; + } catch { + return undefined; + } +} + export interface Website { id: string; name: string; @@ -23,7 +35,7 @@ export class UmamiClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): UmamiClient { const url = env.MESH_PROVISION_UMAMI_URL ?? env.UMAMI_URL; const username = env.UMAMI_USERNAME ?? "admin"; - const password = env.UMAMI_ADMIN_PASSWORD; + const password = readSecret(env.MESH_UMAMI_ADMIN_PASSWORD_FILE) ?? env.UMAMI_ADMIN_PASSWORD; if (!url || !password) { throw new Error("UMAMI url or admin password is not set — umami's own code cannot reach it"); } diff --git a/modules/umami/module.json b/modules/umami/module.json index e18e025..a9bd185 100644 --- a/modules/umami/module.json +++ b/modules/umami/module.json @@ -110,7 +110,8 @@ ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECEIVES": "/var/lib/umami/grants/mesh.json" + "MESH_RECEIVES": "/var/lib/umami/grants/mesh.json", + "MESH_UMAMI_ADMIN_PASSWORD_FILE": "/run/secrets/admin" }, "env-file": [ "/var/lib/umami/provisioner.env"