A secret reaches a process as a file (ADR 0086)

The broker settings take a _FILE twin like the store connections; the
catalogue engine refuses a secret placeholder in a container's env and a
secret-carrying env-file unless the container says why with
secrets-in-environment, which stays in the catalogue and never reaches the
machine.
This commit is contained in:
2026-09-21 10:10:33 +02:00
parent 6b695c82d7
commit 4531f2244f
8 changed files with 245 additions and 5 deletions
+5 -2
View File
@@ -5,9 +5,9 @@ import (
"encoding/json"
"errors"
"fmt"
"github.com/novox/mesh-controller/internal/envfile"
"log"
"os"
"strings"
"time"
amqp "github.com/rabbitmq/amqp091-go"
@@ -107,7 +107,10 @@ func (s *Server) Answers(r Replayer) error {
// Connect opens the control plane's own connection to the broker.
func Connect(enroller Enroller, listener Listener) (*Server, error) {
url := strings.TrimSpace(os.Getenv(AMQPVar))
url, err := envfile.Value(AMQPVar)
if err != nil {
return nil, err
}
if url == "" {
return nil, fmt.Errorf(
"this control plane has no %s, so it cannot reach its broker. Nodes talk to it over "+