A secret reaches a process as a file (ADR 0086)
The broker settings take a _FILE twin like the store connections; the catalogue engine refuses a secret placeholder in a container's env and a secret-carrying env-file unless the container says why with secrets-in-environment, which stays in the catalogue and never reaches the machine.
This commit is contained in:
@@ -0,0 +1,44 @@
|
||||
package envfile
|
||||
|
||||
import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestAFileTwinIsPreferredAndOnlyItsLineEndingGoes(t *testing.T) {
|
||||
path := filepath.Join(t.TempDir(), "value")
|
||||
if err := os.WriteFile(path, []byte(" amqp://u:p@h/ \n"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Setenv("MESH_X", "")
|
||||
t.Setenv("MESH_X_FILE", path)
|
||||
got, err := Value("MESH_X")
|
||||
if err != nil || got != " amqp://u:p@h/ " {
|
||||
t.Fatalf("got %q, %v", got, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestThePlainVariableStillWorks(t *testing.T) {
|
||||
t.Setenv("MESH_Y", " plain ")
|
||||
if got, err := Value("MESH_Y"); err != nil || got != "plain" {
|
||||
t.Fatalf("got %q, %v", got, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestBothSetIsRefused(t *testing.T) {
|
||||
path := filepath.Join(t.TempDir(), "value")
|
||||
_ = os.WriteFile(path, []byte("a"), 0o600)
|
||||
t.Setenv("MESH_Z", "b")
|
||||
t.Setenv("MESH_Z_FILE", path)
|
||||
if _, err := Value("MESH_Z"); err == nil {
|
||||
t.Fatal("two sources were accepted")
|
||||
}
|
||||
}
|
||||
|
||||
func TestAMissingFileIsSaid(t *testing.T) {
|
||||
t.Setenv("MESH_W_FILE", filepath.Join(t.TempDir(), "absent"))
|
||||
if _, err := Value("MESH_W"); err == nil {
|
||||
t.Fatal("a missing file produced a value")
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user