umami: read the admin password from its mounted secret file

The whole-mesh dry-run found umami's runtime crash-looping "admin password is
not set": its `admin` own-secret is mounted at /run/secrets/admin, but the
client read the bare env UMAMI_ADMIN_PASSWORD, which nothing sets. Same shape as
the six tool-runtime credential fixes — read the mounted file first
(MESH_UMAMI_ADMIN_PASSWORD_FILE), falling back to the env. (photos and mailu
remain deeper conversion jobs — a stub app image and a full Mailu config env —
not credential-wiring, tracked separately.)

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-08 18:43:48 +02:00
parent d289e5a928
commit 5973d41966
2 changed files with 15 additions and 2 deletions
+13 -1
View File
@@ -2,6 +2,18 @@
// changes when umami's API does (novox/hq ADR 0039). Both this module's tools and its provisioner
// import it; nothing outside umami does.
import { readFileSync } from "node:fs";
/** Read a secret from the file the mesh mounted it at, if the pointing env is set. */
function readSecret(path: string | undefined): string | undefined {
if (!path) return undefined;
try {
return readFileSync(path, "utf8").trim() || undefined;
} catch {
return undefined;
}
}
export interface Website {
id: string;
name: string;
@@ -23,7 +35,7 @@ export class UmamiClient {
static fromEnv(env: NodeJS.ProcessEnv = process.env): UmamiClient {
const url = env.MESH_PROVISION_UMAMI_URL ?? env.UMAMI_URL;
const username = env.UMAMI_USERNAME ?? "admin";
const password = env.UMAMI_ADMIN_PASSWORD;
const password = readSecret(env.MESH_UMAMI_ADMIN_PASSWORD_FILE) ?? env.UMAMI_ADMIN_PASSWORD;
if (!url || !password) {
throw new Error("UMAMI url or admin password is not set — umami's own code cannot reach it");
}