A secret reaches a process as a file (ADR 0086)

The broker settings take a _FILE twin like the store connections; the
catalogue engine refuses a secret placeholder in a container's env and a
secret-carrying env-file unless the container says why with
secrets-in-environment, which stays in the catalogue and never reaches the
machine.
This commit is contained in:
2026-09-21 10:10:33 +02:00
parent 6b695c82d7
commit 4531f2244f
8 changed files with 245 additions and 5 deletions
+44
View File
@@ -0,0 +1,44 @@
package envfile
import (
"os"
"path/filepath"
"testing"
)
func TestAFileTwinIsPreferredAndOnlyItsLineEndingGoes(t *testing.T) {
path := filepath.Join(t.TempDir(), "value")
if err := os.WriteFile(path, []byte(" amqp://u:p@h/ \n"), 0o600); err != nil {
t.Fatal(err)
}
t.Setenv("MESH_X", "")
t.Setenv("MESH_X_FILE", path)
got, err := Value("MESH_X")
if err != nil || got != " amqp://u:p@h/ " {
t.Fatalf("got %q, %v", got, err)
}
}
func TestThePlainVariableStillWorks(t *testing.T) {
t.Setenv("MESH_Y", " plain ")
if got, err := Value("MESH_Y"); err != nil || got != "plain" {
t.Fatalf("got %q, %v", got, err)
}
}
func TestBothSetIsRefused(t *testing.T) {
path := filepath.Join(t.TempDir(), "value")
_ = os.WriteFile(path, []byte("a"), 0o600)
t.Setenv("MESH_Z", "b")
t.Setenv("MESH_Z_FILE", path)
if _, err := Value("MESH_Z"); err == nil {
t.Fatal("two sources were accepted")
}
}
func TestAMissingFileIsSaid(t *testing.T) {
t.Setenv("MESH_W_FILE", filepath.Join(t.TempDir(), "absent"))
if _, err := Value("MESH_W"); err == nil {
t.Fatal("a missing file produced a value")
}
}