Merge pull request 'The controller reads its credentials from files; every other env-file secret says why' (#31) from feat/secret-not-in-environment into main

This commit was merged in pull request #31.
This commit is contained in:
2026-09-21 11:59:08 +02:00
25 changed files with 85 additions and 47 deletions
+2 -1
View File
@@ -49,7 +49,8 @@
],
"restart-on": [
"app-env"
]
],
"secrets-in-environment": "the runtime reads its SMTP and AMQP settings from the environment; a file twin in the SDK is the per-module work of issue 041"
}
]
}
+2 -1
View File
@@ -60,7 +60,8 @@
"restart-on": [
"amqp-env"
],
"artifact": "runtime"
"artifact": "runtime",
"secrets-in-environment": "the runtime reads MESH_AMQP_* from the environment; a file twin in the SDK is the per-module work of issue 041"
}
],
"build": {
+2 -1
View File
@@ -85,7 +85,8 @@
],
"volumes": [
"/services/baserow/data:/baserow/data"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime-config",
+2 -1
View File
@@ -59,7 +59,8 @@
],
"ports": [
"35621:35621"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}
]
}
+4 -2
View File
@@ -113,7 +113,8 @@
],
"volumes": [
"/services/gitea/gitea:/data"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "admin-bootstrap",
@@ -137,7 +138,8 @@
"/bin/sh",
"-c",
"su-exec git gitea admin user create --admin --username \"$MESH_GITEA_ADMIN_USER\" --email mesh-admin@localhost --password \"$(cat /run/secrets/admin)\" --must-change-password=false || true"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime-config",
+2 -1
View File
@@ -59,7 +59,8 @@
],
"volumes": [
"/services/grafana/data:/var/lib/grafana"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime-config",
+2 -1
View File
@@ -52,7 +52,8 @@
],
"ports": [
"8000"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime-config",
+2 -1
View File
@@ -65,7 +65,8 @@
"volumes": [
"/services/influxdb/data:/var/lib/influxdb2",
"/services/influxdb/config:/etc/influxdb2"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime-config",
+2 -1
View File
@@ -99,7 +99,8 @@
],
"ports": [
"9000"
]
],
"secrets-in-environment": "the API reads its settings from the environment; converting is the per-module work of issue 041"
}
]
}
+2 -1
View File
@@ -96,7 +96,8 @@
],
"ports": [
"8080"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime-config",
+4 -2
View File
@@ -66,7 +66,8 @@
],
"ports": [
"8283"
]
],
"secrets-in-environment": "the runtime reads its settings from the environment; converting is the per-module work of issue 041"
},
{
"id": "runtime-config",
@@ -103,7 +104,8 @@
"restart-on": [
"runtime-config"
],
"artifact": "runtime"
"artifact": "runtime",
"secrets-in-environment": "the runtime reads its settings from the environment; converting is the per-module work of issue 041"
}
],
"build": {
+20 -10
View File
@@ -217,7 +217,8 @@
"env-file": [
"/var/lib/mailu/mailu.env",
"/var/lib/mailu/secret.env"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "redis",
@@ -244,7 +245,8 @@
"volumes": [
"/services/mailu/data/data:/data",
"/services/mailu/data/dkim:/dkim"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "imap",
@@ -259,7 +261,8 @@
"volumes": [
"/services/mailu/data/mail:/mail",
"/services/mailu/data/overrides/dovecot:/overrides:ro"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "smtp",
@@ -274,7 +277,8 @@
"volumes": [
"/services/mailu/data/mailqueue:/queue",
"/services/mailu/data/overrides/postfix:/overrides:ro"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "antispam",
@@ -289,7 +293,8 @@
"volumes": [
"/services/mailu/data/filter:/var/lib/rspamd",
"/services/mailu/data/overrides/rspamd:/etc/rspamd/override.d:ro"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "antivirus",
@@ -303,7 +308,8 @@
],
"volumes": [
"/services/mailu/data/filter:/data"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "webmail",
@@ -318,7 +324,8 @@
"volumes": [
"/services/mailu/data/webmail:/data",
"/services/mailu/data/overrides/roundcube:/overrides:ro"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "webdav",
@@ -332,7 +339,8 @@
],
"volumes": [
"/services/mailu/data/dav:/data"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "fetchmail",
@@ -346,7 +354,8 @@
],
"volumes": [
"/services/mailu/data/data/fetchmail:/data"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "front",
@@ -368,7 +377,8 @@
"volumes": [
"/services/mailu/data/certs:/certs",
"/services/mailu/data/overrides/nginx:/overrides:ro"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime-config",
+2 -1
View File
@@ -74,7 +74,8 @@
"artifact": "runtime",
"restart-on": [
"db-env"
]
],
"secrets-in-environment": "the mesh's own runtime reads MESH_STORE_* from the environment; a file twin in the SDK is the per-module work of issue 041"
}
],
"build": {
+15 -12
View File
@@ -19,6 +19,7 @@
"broker-management": "/var/lib/mesh/mesh-controller/broker-management",
"broker-address": "/var/lib/mesh/mesh-controller/broker-address"
},
"secrets-owner": "65534:65534",
"resources": [
{
"id": "mesh-state",
@@ -26,13 +27,6 @@
"path": "/var/lib/mesh/mesh-controller",
"mode": "0700"
},
{
"id": "control-env",
"type": "file",
"path": "/var/lib/mesh/mesh-controller/control.env",
"mode": "0600",
"content": "MESH_STORE_INVENTORY=${secret:inventory}\nMESH_STORE_IDENTITY=${secret:identity}\nMESH_STORE_LICENCES=${secret:licences}\nMESH_BROKER_AMQP=${secret:broker}\nMESH_BROKER_MANAGEMENT=${secret:broker-management}\nMESH_BROKER_ADDRESS=${secret:broker-address}\n"
},
{
"id": "server",
"type": "container",
@@ -42,14 +36,23 @@
"args": [
"serve"
],
"env-file": [
"/var/lib/mesh/mesh-controller/control.env"
],
"env": {
"MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt"
"MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt",
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
"MESH_STORE_IDENTITY_FILE": "/run/secrets/identity",
"MESH_STORE_LICENCES_FILE": "/run/secrets/licences",
"MESH_BROKER_AMQP_FILE": "/run/secrets/broker",
"MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management",
"MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address"
},
"volumes": [
"mesh-broker-tls:/broker-tls:ro"
"mesh-broker-tls:/broker-tls:ro",
"/var/lib/mesh/mesh-controller/inventory:/run/secrets/inventory:ro",
"/var/lib/mesh/mesh-controller/identity:/run/secrets/identity:ro",
"/var/lib/mesh/mesh-controller/licences:/run/secrets/licences:ro",
"/var/lib/mesh/mesh-controller/broker:/run/secrets/broker:ro",
"/var/lib/mesh/mesh-controller/broker-management:/run/secrets/broker-management:ro",
"/var/lib/mesh/mesh-controller/broker-address:/run/secrets/broker-address:ro"
],
"restart-on": [
"control-env"
+2 -1
View File
@@ -96,7 +96,8 @@
],
"volumes": [
"/services/minio/data/data1-1:/data"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime",
+2 -1
View File
@@ -60,7 +60,8 @@
},
"env-file": [
"/var/lib/model-usage/db.env"
]
],
"secrets-in-environment": "the mesh's own runtime reads MESH_STORE_* from the environment; a file twin in the SDK is the per-module work of issue 041"
}
]
}
+2 -1
View File
@@ -95,7 +95,8 @@
],
"volumes": [
"/services/mongodb/db-data:/data/db"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime",
+2 -1
View File
@@ -91,7 +91,8 @@
],
"volumes": [
"/services/mssql/db-data:/var/opt/mssql"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime",
+2 -1
View File
@@ -78,7 +78,8 @@
],
"volumes": [
"/services/n8n/n8n-data:/home/node/.n8n"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}
]
}
+2 -1
View File
@@ -87,7 +87,8 @@
],
"volumes": [
"/services/nextcloud/html:/var/www/html"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime-config",
+2 -1
View File
@@ -109,7 +109,8 @@
"/services/only-office/rabbitmq:/var/lib/rabbitmq",
"/services/only-office/redis:/var/lib/redis",
"/services/only-office/fonts:/usr/share/fonts/truetype/custom"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}
]
}
+2 -1
View File
@@ -74,7 +74,8 @@
],
"ports": [
"9000"
]
],
"secrets-in-environment": "the server reads its settings from the environment; converting is the per-module work of issue 041"
},
{
"id": "admin-client",
+2 -1
View File
@@ -70,7 +70,8 @@
],
"ports": [
"8080"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime-config",
+2 -1
View File
@@ -103,7 +103,8 @@
"volumes": [
"/var/lib/step-ca:/home/step",
"/var/lib/mesh/step-ca:/run/mesh:ro"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
}
]
}
+2 -1
View File
@@ -101,7 +101,8 @@
],
"ports": [
"3000"
]
],
"secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041"
},
{
"id": "runtime",