A secret reaches a process as a file (ADR 0086)
The broker settings take a _FILE twin like the store connections; the catalogue engine refuses a secret placeholder in a container's env and a secret-carrying env-file unless the container says why with secrets-in-environment, which stays in the catalogue and never reaches the machine.
This commit is contained in:
@@ -16,6 +16,7 @@ import (
|
||||
"encoding/pem"
|
||||
"errors"
|
||||
"fmt"
|
||||
"github.com/novox/mesh-controller/internal/envfile"
|
||||
"os"
|
||||
"strings"
|
||||
)
|
||||
@@ -40,7 +41,10 @@ var ErrNotConfigured = errors.New("this control plane has not been told about it
|
||||
|
||||
// FromEnvironment reads the two settings, if they are there.
|
||||
func FromEnvironment() (Broker, error) {
|
||||
address := strings.TrimSpace(os.Getenv(AddressVar))
|
||||
address, err := envfile.Value(AddressVar)
|
||||
if err != nil {
|
||||
return Broker{}, err
|
||||
}
|
||||
path := strings.TrimSpace(os.Getenv(CertificateVar))
|
||||
|
||||
if address == "" && path == "" {
|
||||
|
||||
Reference in New Issue
Block a user