feat: load Docker secret files so the production stack can boot

deploy/stack.yaml passes DATABASE_URL_FILE, AWS_ACCESS_KEY_ID_FILE,
OPERATOR_PASSWORD_FILE and the provider tokens as Swarm secret paths, but the
runtime only ever read the plain names. That stack could not start: the database
URL and R2 credentials were absent, and operator login raised KeyError, so it
returned 500 instead of the intended 503.

local/secrets.py resolves every <NAME>_FILE into <NAME> before configuration is
read, from the API, worker and bootstrap entrypoints. It fails closed on an
unreadable or empty secret and on a name supplied both directly and as a file,
because starting with a credential nobody intended is worse than not starting.
Only one trailing newline is stripped, so a generated password keeps any
whitespace that belongs to it, and no value reaches an error message.

The stack also passed OPERATOR_USER while the Kanban authenticates by email;
it now passes OPERATOR_EMAIL, matching the runtime.

The release gate checked this by searching local/secrets.py for the literal
"DATABASE_URL_FILE", which would pass for any file containing that string. It
now loads the module and makes it resolve every secret the stack declares, and
asserts it fails closed on a missing one. Four marker strings that stopped
matching when R2 support landed are removed rather than left to rot; the two
that still describe real blockers stay, so the gate continues to refuse a
release while payment and messaging adapters are fake.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-21 11:36:59 -03:00
parent 9b38c9fe3d
commit 341f154c36
9 changed files with 240 additions and 13 deletions

View File

@@ -17,7 +17,7 @@ REQUIRED = (
'IMAGE_TAG', 'PUBLIC_ORIGIN', 'PUBLIC_HOST', 'KANBAN_HOST',
'SITE_PORT', 'KANBAN_PORT',
'R2_ENDPOINT', 'R2_PUBLIC_ENDPOINT', 'R2_BUCKET',
'POSTGRES_DB', 'POSTGRES_USER', 'APP_DB_USER', 'POSTGRES_VOLUME', 'OPERATOR_USER',
'POSTGRES_DB', 'POSTGRES_USER', 'APP_DB_USER', 'POSTGRES_VOLUME', 'OPERATOR_EMAIL',
'STORAGE_QUOTA_BYTES', 'OWNER_UPLOAD_QUOTA_BYTES', 'MAX_UPLOAD_BYTES',
'UPLOAD_PART_BYTES', 'MAX_PENDING_UPLOADS', 'SCAN_MAX_BYTES',
'PAYMENT_ADAPTER', 'FREIGHT_ADAPTER', 'TINY_ADAPTER', 'WHATSAPP_ADAPTER',
@@ -33,13 +33,12 @@ IMAGE_REPOSITORY = re.compile(
DNS = re.compile(r'^(?=.{1,253}$)(?:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?\.)+[a-z]{2,63}$')
NAME = re.compile(r'^[a-zA-Z0-9][a-zA-Z0-9_.-]{2,127}$')
SOURCE_BLOCKERS = {
'local/adapters.py': (
'This runtime only supports APP_ENV=local',
'Only local S3 storage is supported',
),
# Markers must name something that is still true, or the gate weakens without
# failing. Four entries here described a local-only runtime and stopped
# matching when R2 support landed; they were removed rather than left to rot.
# What remains is the real blocker: no production payment or messaging adapter
# exists, so these lines must change before a release can be meaningful.
'local/app.py': (
"allowed_hosts=['localhost', '127.0.0.1']",
"'environment': 'local'",
'payment = FakePayment()',
),
'local/worker.py': (
@@ -55,12 +54,63 @@ def source_errors(root=ROOT):
for marker in markers:
if marker in text:
errors.append(f'{relative} remains local-only: {marker}')
secrets_module = root / 'local' / 'secrets.py'
if not secrets_module.exists() or 'DATABASE_URL_FILE' not in secrets_module.read_text():
errors.append('local runtime does not load the production Docker secret *_FILE settings')
errors.extend(secret_loading_errors(root))
return errors
def secret_loading_errors(root=ROOT):
"""Exercise the secret loader instead of grepping it.
Searching for a string passes as soon as someone writes that string, and
fails when a working implementation happens to spell it differently. Load the
module and make it resolve a real file.
"""
import importlib.util
import tempfile
module_path = root / 'local' / 'secrets.py'
if not module_path.exists():
return ['local runtime does not load the production Docker secret *_FILE settings']
try:
spec = importlib.util.spec_from_file_location('_preflight_secrets', module_path)
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)
except Exception as exc:
return [f'local/secrets.py could not be loaded: {exc}']
stack_names = set()
stack = root / 'deploy' / 'stack.yaml'
if stack.exists():
for line in stack.read_text().splitlines():
if '_FILE:' in line:
key = line.split(':')[0].strip()
# The database image consumes this one; the application does not.
if key and key != 'POSTGRES_PASSWORD_FILE':
stack_names.add(key[:-len('_FILE')])
failures = []
with tempfile.TemporaryDirectory() as directory:
for name in sorted(stack_names):
path = Path(directory) / name
path.write_text('resolved-value\n', encoding='utf-8')
environ = {f'{name}_FILE': str(path)}
try:
module.load(environ)
except Exception as exc:
failures.append(f'{name}_FILE is not resolved by local/secrets.py: {exc}')
continue
if environ.get(name) != 'resolved-value':
failures.append(f'{name}_FILE did not produce {name}')
# A missing secret must stop the service, never start it unconfigured.
try:
module.load({'DATABASE_URL_FILE': str(Path(directory) / 'absent')})
except Exception:
pass
else:
failures.append('local/secrets.py does not fail closed on an unreadable secret')
return failures
def config_errors(values):
errors = []
for name in APPROVALS:

View File

@@ -9,7 +9,8 @@ x-app-environment: &app-environment
AWS_ACCESS_KEY_ID_FILE: /run/secrets/r2_access_key_id
AWS_SECRET_ACCESS_KEY_FILE: /run/secrets/r2_secret_access_key
AWS_DEFAULT_REGION: auto
OPERATOR_USER: ${OPERATOR_USER:?set OPERATOR_USER}
# The Kanban authenticates by email; the runtime reads OPERATOR_EMAIL.
OPERATOR_EMAIL: ${OPERATOR_EMAIL:?set OPERATOR_EMAIL}
OPERATOR_PASSWORD_FILE: /run/secrets/operator_password
PAYMENT_ADAPTER: ${PAYMENT_ADAPTER:?set PAYMENT_ADAPTER}
FREIGHT_ADAPTER: ${FREIGHT_ADAPTER:?set FREIGHT_ADAPTER}

View File

@@ -27,7 +27,7 @@ def valid_config():
'POSTGRES_USER': 'dtf_admin',
'APP_DB_USER': 'dtf_app',
'POSTGRES_VOLUME': 'dtf-postgres-data',
'OPERATOR_USER': 'dtf-operator',
'OPERATOR_EMAIL': 'operador@example.com',
'STORAGE_QUOTA_BYTES': '53687091200',
'OWNER_UPLOAD_QUOTA_BYTES': '10737418240',
'MAX_UPLOAD_BYTES': '5368709120',