chore: remove the unused second stack definition
deploy/stack.yaml arrived in the first commit and was never deployed. Portainer runs the repository's docker-compose.yml. Keeping both meant two definitions drifting apart, with the documentation naming the one nobody used, which is how the credential question came up at all. The hardening it offered is narrower than it looks: Docker secrets keep values out of docker inspect and the Portainer console, but local/secrets.py loads them into the process environment regardless, and anyone able to read docker inspect can already read the secret files. With a single Portainer user, the benefit that remains does not outweigh maintaining a divergent copy. local/secrets.py stays: inert against the deployed file, and it lets a stack switch to Docker secrets later without touching code. The preflight and its tests degrade cleanly when no such stack is present. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,9 +1,9 @@
|
||||
"""Resolve Docker secret files into the environment before configuration is read.
|
||||
|
||||
Swarm mounts each secret as a file and the stack passes its path as `<NAME>_FILE`.
|
||||
Nothing read `_FILE` settings, so `deploy/stack.yaml` could not boot: the runtime
|
||||
looked for `DATABASE_URL`, `AWS_ACCESS_KEY_ID` and `OPERATOR_PASSWORD` while the
|
||||
stack supplied only the `_FILE` form.
|
||||
The deployed `docker-compose.yml` passes credentials as plain environment
|
||||
variables, so this module is inert there. It exists so a stack can supply them as
|
||||
Docker secrets instead without any code change; see `ROADMAP.md` 2.12.
|
||||
|
||||
Call `load()` in every entrypoint before any configuration is read.
|
||||
|
||||
@@ -12,9 +12,9 @@ secrets` elsewhere in the package to the standard library, not to this file.
|
||||
"""
|
||||
import os
|
||||
|
||||
# The settings production supplies as secret files. Any other `*_FILE` variable is
|
||||
# The settings a stack may supply as secret files. Any other `*_FILE` variable is
|
||||
# resolved the same way; this list documents the contract and is what the release
|
||||
# gate checks against, so keep it in step with `deploy/stack.yaml`.
|
||||
# gate checks against.
|
||||
SECRET_FILE_SETTINGS = (
|
||||
'DATABASE_URL',
|
||||
'DATABASE_ADMIN_URL',
|
||||
|
||||
Reference in New Issue
Block a user