Read credentials from files, not only the environment
Found by packaging the service for Railiance (rapp-canned-prompts). Every other rapp in the fleet mounts its database credential as a file; this service could only read CANNED_PROMPTS_DATABASE_URL from the environment, which would have put a database password into kubectl describe, into crash dumps, and in reach of anything able to read /proc. Adds CANNED_PROMPTS_DATABASE_URL_FILE and CANNED_PROMPTS_PUBLISH_TOKEN_FILE. A mounted secret stays a file. When both forms are set the file wins, because a rotated secret must take effect rather than be shadowed by a stale env var, and an unreadable secret file fails loudly rather than falling back to a value that may be older. Service tests 33 -> 36. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
This commit is contained in:
parent
cb133f3673
commit
0fb7150956
6 changed files with 79 additions and 5 deletions
|
|
@ -27,6 +27,14 @@ export CANNED_PROMPTS_DATABASE_URL=postgresql+psycopg://...
|
|||
.venv/bin/uvicorn canned_prompts_service.api:create_app --factory
|
||||
```
|
||||
|
||||
Credentials may arrive as **files** rather than environment variables —
|
||||
`CANNED_PROMPTS_DATABASE_URL_FILE` and `CANNED_PROMPTS_PUBLISH_TOKEN_FILE` —
|
||||
which is how they are supplied in the cluster. An env var holding a password is
|
||||
visible in `kubectl describe`, in crash dumps, and to anything that can read
|
||||
`/proc`; a mounted secret should stay a file. When both forms are set the file
|
||||
wins, because a rotated secret must take effect rather than be shadowed by a
|
||||
stale env var.
|
||||
|
||||
`CANNED_PROMPTS_DATABASE_URL` has **no default**. A service that silently falls
|
||||
back to a local database when its real one is misconfigured is worse than one
|
||||
that refuses to start.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue