module fixes from the whole-mesh dry-run: fail2ban capability + tool-runtime credential wiring #20
+13
-1
@@ -2,6 +2,18 @@
|
||||
// changes when umami's API does (novox/hq ADR 0039). Both this module's tools and its provisioner
|
||||
// import it; nothing outside umami does.
|
||||
|
||||
import { readFileSync } from "node:fs";
|
||||
|
||||
/** Read a secret from the file the mesh mounted it at, if the pointing env is set. */
|
||||
function readSecret(path: string | undefined): string | undefined {
|
||||
if (!path) return undefined;
|
||||
try {
|
||||
return readFileSync(path, "utf8").trim() || undefined;
|
||||
} catch {
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
|
||||
export interface Website {
|
||||
id: string;
|
||||
name: string;
|
||||
@@ -23,7 +35,7 @@ export class UmamiClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): UmamiClient {
|
||||
const url = env.MESH_PROVISION_UMAMI_URL ?? env.UMAMI_URL;
|
||||
const username = env.UMAMI_USERNAME ?? "admin";
|
||||
const password = env.UMAMI_ADMIN_PASSWORD;
|
||||
const password = readSecret(env.MESH_UMAMI_ADMIN_PASSWORD_FILE) ?? env.UMAMI_ADMIN_PASSWORD;
|
||||
if (!url || !password) {
|
||||
throw new Error("UMAMI url or admin password is not set — umami's own code cannot reach it");
|
||||
}
|
||||
|
||||
@@ -110,7 +110,8 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_RECEIVES": "/var/lib/umami/grants/mesh.json"
|
||||
"MESH_RECEIVES": "/var/lib/umami/grants/mesh.json",
|
||||
"MESH_UMAMI_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
|
||||
},
|
||||
"env-file": [
|
||||
"/var/lib/umami/provisioner.env"
|
||||
|
||||
Reference in New Issue
Block a user