Five modules keep their own secrets from the vault, under local names; route-proxy declares its bases
gitea, umami, influxdb, icecast and mailu require a secret and keep each of theirs under a local name (novox/hq ADR 0094); the broker account stays their own. The route proxy's recipe starts FROM the bases its manifest declares (ADR 0097).
This commit is contained in:
@@ -6,7 +6,8 @@
|
||||
],
|
||||
"requires": [
|
||||
"postgres-database",
|
||||
"route"
|
||||
"route",
|
||||
"secret"
|
||||
],
|
||||
"contributes": {
|
||||
"postgres-database": {
|
||||
@@ -22,7 +23,12 @@
|
||||
"route": "/var/lib/mailu/route.json"
|
||||
},
|
||||
"secrets": {
|
||||
"postgres-database": "/var/lib/mailu/database.secret"
|
||||
"postgres-database": "/var/lib/mailu/database.secret",
|
||||
"secret": {
|
||||
"secret-key": "/var/lib/mailu/secret-key.secret",
|
||||
"admin": "/var/lib/mailu/admin.secret",
|
||||
"api-token": "/var/lib/mailu/api-token.secret"
|
||||
}
|
||||
},
|
||||
"emits": [
|
||||
"module.mailu.user.created",
|
||||
@@ -67,9 +73,6 @@
|
||||
}
|
||||
],
|
||||
"own-secrets": {
|
||||
"secret-key": "/var/lib/mailu/secret-key.secret",
|
||||
"admin": "/var/lib/mailu/admin.secret",
|
||||
"api-token": "/var/lib/mailu/api-token.secret",
|
||||
"broker": "/var/lib/mesh/mailu/broker"
|
||||
},
|
||||
"resources": [
|
||||
|
||||
Reference in New Issue
Block a user