ADR 0086. mesh-controller mounts its six own secrets and names them with _FILE twins, so no credential of its own reaches its environment. The 35 containers that still read a secret through an env-file carry secrets-in-environment with the reason; converting each where its software accepts a path is the per-module work of issue 041.
57 lines
1.8 KiB
JSON
57 lines
1.8 KiB
JSON
{
|
|
"module": "amqp-email-forwarder",
|
|
"version": "1",
|
|
"slug": "emailfwd",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"amqp"
|
|
],
|
|
"contributes": {},
|
|
"binds": {
|
|
"amqp": "/var/lib/amqp-email-forwarder/amqp.json"
|
|
},
|
|
"secrets": {
|
|
"amqp": "/var/lib/amqp-email-forwarder/amqp.secret"
|
|
},
|
|
"own-secrets": {
|
|
"smtp-user": "/var/lib/amqp-email-forwarder/smtp-user.secret",
|
|
"smtp-password": "/var/lib/amqp-email-forwarder/smtp-password.secret"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/amqp-email-forwarder",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "app-env",
|
|
"type": "file",
|
|
"path": "/var/lib/amqp-email-forwarder/app.env",
|
|
"mode": "0600",
|
|
"content": "AMQP_HOST=${bound:amqp:at}\nAMQP_PORT=${bound:amqp:port}\nAMQP_USER=${bound:amqp:as}\nAMQP_PASSWORD=${secret:amqp}\nAMQP_VHOST=EMAILDELIVERY_T\nAMQP_EXCHANGE=News.TransactionalEmailing.Command\nAMQP_QUEUE=email-forwarder\nAMQP_URL=amqp://${bound:amqp:as}:${secret:amqp}@${bound:amqp:at}:${bound:amqp:port}/EMAILDELIVERY_T\nSMTP_HOST=mail.novox.be\nSMTP_PORT=587\nSMTP_USER=${secret:smtp-user}\nSMTP_PASSWORD=${secret:smtp-password}\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "amqp-email-forwarder"
|
|
},
|
|
{
|
|
"id": "app",
|
|
"type": "container",
|
|
"name": "amqp-email-forwarder",
|
|
"image": "registry-api.novox.be/novox/amqp-email-forwarder@sha256:f76d34646d9d3b2098c72688a63f6ae656f1888ffcb2f90a9c8dd2a44ad7f8af",
|
|
"network": "amqp-email-forwarder",
|
|
"env-file": [
|
|
"/var/lib/amqp-email-forwarder/app.env"
|
|
],
|
|
"restart-on": [
|
|
"app-env"
|
|
],
|
|
"secrets-in-environment": "the runtime reads its SMTP and AMQP settings from the environment; a file twin in the SDK is the per-module work of issue 041"
|
|
}
|
|
]
|
|
}
|