From 7bda56d2223fb677e184eeb97e0079e5a2db8aac Mon Sep 17 00:00:00 2001 From: Schalli Date: Tue, 11 Aug 2026 14:25:36 +0200 Subject: [PATCH] build: refuse to start without an encryption key The base compose file carried a hardcoded fallback key, so a stack whose .env never set the variable started anyway and encrypted every stored credential (LDAP bind, calendar, SMTP, DKV and tender mailboxes) with a value that is public in this repository. That is encryption which looks present and protects nothing. Both compose files now use the ${VAR:?message} form, so an unset or empty key fails at compose level with a message naming the variable and how to generate one, instead of starting with a known key or dying later inside the API with a stack trace. Verified both ways: without the variable `docker compose config` exits 1 and prints the hint; with a key present it exits 0. Consequence for a fresh clone: the local stack no longer comes up until CALENDAR_ENCRYPTION_KEY is set in .env. That is the point. Co-Authored-By: Claude Opus 5 (1M context) --- docker-compose.prod.yml | 5 ++++- docker-compose.yml | 10 +++++++++- 2 files changed, 13 insertions(+), 2 deletions(-) diff --git a/docker-compose.prod.yml b/docker-compose.prod.yml index 2c16f70..f676436 100644 --- a/docker-compose.prod.yml +++ b/docker-compose.prod.yml @@ -41,7 +41,10 @@ services: TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-} TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera } TESSERA_APP_URL: ${APP_URL:-http://localhost:3000} - CALENDAR_ENCRYPTION_KEY: ${CALENDAR_ENCRYPTION_KEY} + # Unset used to resolve to an empty value and only fail later, inside the + # API, with a stack trace. Fail at compose level with a usable message + # instead. Generate with: openssl rand -hex 32 + CALENDAR_ENCRYPTION_KEY: "${CALENDAR_ENCRYPTION_KEY:?set CALENDAR_ENCRYPTION_KEY in .env, generate one with openssl rand -hex 32}" healthcheck: test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"] interval: 10s diff --git a/docker-compose.yml b/docker-compose.yml index 9b07494..49a7932 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -43,7 +43,15 @@ services: TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-} TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera } TESSERA_APP_URL: ${TESSERA_APP_URL:-http://localhost:3000} - CALENDAR_ENCRYPTION_KEY: ${CALENDAR_ENCRYPTION_KEY:-5dbbaba2051177d5f16c44bbe2a20e40cde5634c00cc2d5f4100497ca5299dfe} + # No default on purpose: this key decrypts every stored credential + # (LDAP bind, calendar, SMTP, DKV and tender mailboxes). A built-in + # fallback would let a stack start and encrypt everything with a value + # that is public in this repository -- encryption that looks present and + # protects nothing. Failing to start is the honest outcome. + # Generate one with: openssl rand -hex 32 + # Keep it with your backups but stored separately from the database dump; + # losing it means re-entering every stored credential by hand. + CALENDAR_ENCRYPTION_KEY: "${CALENDAR_ENCRYPTION_KEY:?set CALENDAR_ENCRYPTION_KEY in .env, generate one with openssl rand -hex 32}" healthcheck: test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"] interval: 10s