chore: remove the unused second stack definition
deploy/stack.yaml arrived in the first commit and was never deployed. Portainer runs the repository's docker-compose.yml. Keeping both meant two definitions drifting apart, with the documentation naming the one nobody used, which is how the credential question came up at all. The hardening it offered is narrower than it looks: Docker secrets keep values out of docker inspect and the Portainer console, but local/secrets.py loads them into the process environment regardless, and anyone able to read docker inspect can already read the secret files. With a single Portainer user, the benefit that remains does not outweigh maintaining a divergent copy. local/secrets.py stays: inert against the deployed file, and it lets a stack switch to Docker secrets later without touching code. The preflight and its tests degrade cleanly when no such stack is present. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -35,7 +35,6 @@ jobs:
|
||||
# taken on the machine itself. Known occupants of that host:
|
||||
# 8000, 9443 Portainer (the Edge tunnel and its UI)
|
||||
# 18080/18081 the production dtf-cloud stack (docker-compose.yml defaults)
|
||||
# 8080/8081 deploy/stack.yaml defaults
|
||||
# 9000/9001 MinIO defaults elsewhere
|
||||
# This block avoids all of them. Ephemeral ports are not an option: the
|
||||
# published port is baked into PUBLIC_ORIGIN, ALLOWED_ORIGINS and the CSP
|
||||
|
||||
Reference in New Issue
Block a user