fix: support arbitrary production database passwords
All checks were successful
Build and deploy / Validate source (push) Successful in 7s
Build and deploy / Publish images and notify Portainer (push) Successful in 49s

This commit is contained in:
Cauê Faleiros
2026-09-18 12:18:43 -03:00
parent fbb620bd85
commit 9d348ca893
3 changed files with 32 additions and 4 deletions

View File

@@ -2,7 +2,10 @@ version: "3.8"
x-app-environment: &app-environment x-app-environment: &app-environment
APP_ENV: production APP_ENV: production
DATABASE_URL: postgresql://dtf_app:${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}@db:5432/dtf DATABASE_HOST: db
DATABASE_NAME: dtf
DATABASE_USER: dtf_app
DATABASE_PASSWORD: ${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}
S3_ENDPOINT: ${R2_ENDPOINT:?set R2_ENDPOINT} S3_ENDPOINT: ${R2_ENDPOINT:?set R2_ENDPOINT}
S3_PUBLIC_ENDPOINT: ${R2_ENDPOINT:?set R2_ENDPOINT} S3_PUBLIC_ENDPOINT: ${R2_ENDPOINT:?set R2_ENDPOINT}
S3_BUCKET: ${R2_BUCKET:?set R2_BUCKET} S3_BUCKET: ${R2_BUCKET:?set R2_BUCKET}
@@ -51,7 +54,10 @@ services:
image: ${API_IMAGE:-gitea.blyzer.com.br/blyzer/dtf-api}:${IMAGE_TAG:-latest} image: ${API_IMAGE:-gitea.blyzer.com.br/blyzer/dtf-api}:${IMAGE_TAG:-latest}
command: python -m local.bootstrap command: python -m local.bootstrap
environment: environment:
DATABASE_ADMIN_URL: postgresql://dtf_admin:${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}@db:5432/dtf DATABASE_ADMIN_HOST: db
DATABASE_ADMIN_NAME: dtf
DATABASE_ADMIN_USER: dtf_admin
DATABASE_ADMIN_PASSWORD: ${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}
APP_DB_USER: dtf_app APP_DB_USER: dtf_app
APP_DB_PASSWORD: ${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD} APP_DB_PASSWORD: ${POSTGRES_PASSWORD:?set POSTGRES_PASSWORD}
networks: [backend] networks: [backend]

View File

@@ -4,9 +4,21 @@ from pathlib import Path
import psycopg import psycopg
from psycopg import sql from psycopg import sql
def admin_connect():
if os.environ.get('DATABASE_ADMIN_HOST'):
return psycopg.connect(
host=os.environ['DATABASE_ADMIN_HOST'],
dbname=os.environ['DATABASE_ADMIN_NAME'],
user=os.environ['DATABASE_ADMIN_USER'],
password=os.environ['DATABASE_ADMIN_PASSWORD'],
)
return psycopg.connect(os.environ['DATABASE_ADMIN_URL'])
def main(): def main():
role = os.environ['APP_DB_USER'] role = os.environ['APP_DB_USER']
with psycopg.connect(os.environ['DATABASE_ADMIN_URL']) as c: with admin_connect() as c:
admin, database = c.execute('SELECT current_user,current_database()').fetchone() admin, database = c.execute('SELECT current_user,current_database()').fetchone()
if role == admin: if role == admin:
raise RuntimeError('Application and database administrator must differ') raise RuntimeError('Application and database administrator must differ')

View File

@@ -4,9 +4,19 @@ import psycopg
from psycopg.rows import dict_row from psycopg.rows import dict_row
def connect(): def connect():
# Production passes credentials as discrete libpq fields. This avoids
# treating characters in a generated password as URL syntax. Local and
# test environments retain DATABASE_URL compatibility.
if os.environ.get('DATABASE_HOST'):
return psycopg.connect(
host=os.environ['DATABASE_HOST'],
dbname=os.environ['DATABASE_NAME'],
user=os.environ['DATABASE_USER'],
password=os.environ['DATABASE_PASSWORD'],
row_factory=dict_row,
)
return psycopg.connect(os.environ['DATABASE_URL'], row_factory=dict_row) return psycopg.connect(os.environ['DATABASE_URL'], row_factory=dict_row)
def initialize(): def initialize():
with connect() as c: with connect() as c:
c.execute(Path(__file__).with_name('schema.sql').read_text()) c.execute(Path(__file__).with_name('schema.sql').read_text())