nextcloud: give the admin password a real _FILE variant, not an env-file
The mesh's own check caught it: an env-file-loaded secret still reaches the process environment, readable via docker inspect and /proc (hq 04-ISSUES/041) -- the same class of exposure the file-based delivery exists to avoid. Added MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE support to the client, matching the pattern the minio client already uses, and mounted the sealed admin secret directly rather than writing it into an env-file.
This commit is contained in:
@@ -98,13 +98,6 @@
|
||||
"content": "{}\n",
|
||||
"merge": "json"
|
||||
},
|
||||
{
|
||||
"id": "runtime-admin-env",
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/nextcloud/admin.env",
|
||||
"mode": "0600",
|
||||
"content": "MESH_NEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\n"
|
||||
},
|
||||
{
|
||||
"id": "runtime",
|
||||
"type": "container",
|
||||
@@ -113,15 +106,14 @@
|
||||
"volumes": [
|
||||
"/var/lib/mesh/nextcloud/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/nextcloud/config.json:/run/config/config.json:ro",
|
||||
"/var/lib/nextcloud-module/admin.secret:/run/secrets/admin:ro",
|
||||
"/var/run/docker.sock:/var/run/docker.sock"
|
||||
],
|
||||
"env-file": [
|
||||
"/var/lib/mesh/nextcloud/admin.env"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_NEXTCLOUD_URL": "http://127.0.0.1:80",
|
||||
"MESH_NEXTCLOUD_CONFIG_FILE": "/run/config/config.json"
|
||||
"MESH_NEXTCLOUD_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
|
||||
},
|
||||
"restart-on": [
|
||||
"runtime-config"
|
||||
|
||||
Reference in New Issue
Block a user