diff --git a/docker-compose.prod.yml b/docker-compose.prod.yml index 2c16f70..f676436 100644 --- a/docker-compose.prod.yml +++ b/docker-compose.prod.yml @@ -41,7 +41,10 @@ services: TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-} TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera } TESSERA_APP_URL: ${APP_URL:-http://localhost:3000} - CALENDAR_ENCRYPTION_KEY: ${CALENDAR_ENCRYPTION_KEY} + # Unset used to resolve to an empty value and only fail later, inside the + # API, with a stack trace. Fail at compose level with a usable message + # instead. Generate with: openssl rand -hex 32 + CALENDAR_ENCRYPTION_KEY: "${CALENDAR_ENCRYPTION_KEY:?set CALENDAR_ENCRYPTION_KEY in .env, generate one with openssl rand -hex 32}" healthcheck: test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"] interval: 10s diff --git a/docker-compose.yml b/docker-compose.yml index 9b07494..49a7932 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -43,7 +43,15 @@ services: TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-} TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera } TESSERA_APP_URL: ${TESSERA_APP_URL:-http://localhost:3000} - CALENDAR_ENCRYPTION_KEY: ${CALENDAR_ENCRYPTION_KEY:-5dbbaba2051177d5f16c44bbe2a20e40cde5634c00cc2d5f4100497ca5299dfe} + # No default on purpose: this key decrypts every stored credential + # (LDAP bind, calendar, SMTP, DKV and tender mailboxes). A built-in + # fallback would let a stack start and encrypt everything with a value + # that is public in this repository -- encryption that looks present and + # protects nothing. Failing to start is the honest outcome. + # Generate one with: openssl rand -hex 32 + # Keep it with your backups but stored separately from the database dump; + # losing it means re-entering every stored credential by hand. + CALENDAR_ENCRYPTION_KEY: "${CALENDAR_ENCRYPTION_KEY:?set CALENDAR_ENCRYPTION_KEY in .env, generate one with openssl rand -hex 32}" healthcheck: test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"] interval: 10s