A secret reaches a process as a file (ADR 0086)
The broker settings take a _FILE twin like the store connections; the catalogue engine refuses a secret placeholder in a container's env and a secret-carrying env-file unless the container says why with secrets-in-environment, which stays in the catalogue and never reaches the machine.
This commit is contained in:
@@ -16,6 +16,7 @@ import (
|
||||
"encoding/pem"
|
||||
"errors"
|
||||
"fmt"
|
||||
"github.com/novox/mesh-controller/internal/envfile"
|
||||
"os"
|
||||
"strings"
|
||||
)
|
||||
@@ -40,7 +41,10 @@ var ErrNotConfigured = errors.New("this control plane has not been told about it
|
||||
|
||||
// FromEnvironment reads the two settings, if they are there.
|
||||
func FromEnvironment() (Broker, error) {
|
||||
address := strings.TrimSpace(os.Getenv(AddressVar))
|
||||
address, err := envfile.Value(AddressVar)
|
||||
if err != nil {
|
||||
return Broker{}, err
|
||||
}
|
||||
path := strings.TrimSpace(os.Getenv(CertificateVar))
|
||||
|
||||
if address == "" && path == "" {
|
||||
|
||||
@@ -5,10 +5,10 @@ import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"github.com/novox/mesh-controller/internal/envfile"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"os"
|
||||
"regexp"
|
||||
"strings"
|
||||
"time"
|
||||
@@ -42,7 +42,10 @@ type Management struct {
|
||||
|
||||
// ManagementFromEnvironment reads where the management API is, if it is configured.
|
||||
func ManagementFromEnvironment() (*Management, error) {
|
||||
raw := strings.TrimSpace(os.Getenv(ManagementVar))
|
||||
raw, err := envfile.Value(ManagementVar)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if raw == "" {
|
||||
return nil, ErrNotConfigured
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user