build: refuse to start without an encryption key
The base compose file carried a hardcoded fallback key, so a stack whose .env
never set the variable started anyway and encrypted every stored credential
(LDAP bind, calendar, SMTP, DKV and tender mailboxes) with a value that is
public in this repository. That is encryption which looks present and protects
nothing.
Both compose files now use the ${VAR:?message} form, so an unset or empty key
fails at compose level with a message naming the variable and how to generate
one, instead of starting with a known key or dying later inside the API with a
stack trace.
Verified both ways: without the variable `docker compose config` exits 1 and
prints the hint; with a key present it exits 0.
Consequence for a fresh clone: the local stack no longer comes up until
CALENDAR_ENCRYPTION_KEY is set in .env. That is the point.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -41,7 +41,10 @@ services:
|
|||||||
TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-}
|
TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-}
|
||||||
TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera <noreply@tessera.local>}
|
TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera <noreply@tessera.local>}
|
||||||
TESSERA_APP_URL: ${APP_URL:-http://localhost:3000}
|
TESSERA_APP_URL: ${APP_URL:-http://localhost:3000}
|
||||||
CALENDAR_ENCRYPTION_KEY: ${CALENDAR_ENCRYPTION_KEY}
|
# Unset used to resolve to an empty value and only fail later, inside the
|
||||||
|
# API, with a stack trace. Fail at compose level with a usable message
|
||||||
|
# instead. Generate with: openssl rand -hex 32
|
||||||
|
CALENDAR_ENCRYPTION_KEY: "${CALENDAR_ENCRYPTION_KEY:?set CALENDAR_ENCRYPTION_KEY in .env, generate one with openssl rand -hex 32}"
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"]
|
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"]
|
||||||
interval: 10s
|
interval: 10s
|
||||||
|
|||||||
+9
-1
@@ -43,7 +43,15 @@ services:
|
|||||||
TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-}
|
TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-}
|
||||||
TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera <tessera@tessera.local>}
|
TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera <tessera@tessera.local>}
|
||||||
TESSERA_APP_URL: ${TESSERA_APP_URL:-http://localhost:3000}
|
TESSERA_APP_URL: ${TESSERA_APP_URL:-http://localhost:3000}
|
||||||
CALENDAR_ENCRYPTION_KEY: ${CALENDAR_ENCRYPTION_KEY:-5dbbaba2051177d5f16c44bbe2a20e40cde5634c00cc2d5f4100497ca5299dfe}
|
# No default on purpose: this key decrypts every stored credential
|
||||||
|
# (LDAP bind, calendar, SMTP, DKV and tender mailboxes). A built-in
|
||||||
|
# fallback would let a stack start and encrypt everything with a value
|
||||||
|
# that is public in this repository -- encryption that looks present and
|
||||||
|
# protects nothing. Failing to start is the honest outcome.
|
||||||
|
# Generate one with: openssl rand -hex 32
|
||||||
|
# Keep it with your backups but stored separately from the database dump;
|
||||||
|
# losing it means re-entering every stored credential by hand.
|
||||||
|
CALENDAR_ENCRYPTION_KEY: "${CALENDAR_ENCRYPTION_KEY:?set CALENDAR_ENCRYPTION_KEY in .env, generate one with openssl rand -hex 32}"
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"]
|
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"]
|
||||||
interval: 10s
|
interval: 10s
|
||||||
|
|||||||
Reference in New Issue
Block a user