diff --git a/backend/src/config/secret-bundle.ts b/backend/src/config/secret-bundle.ts index 3da8e6fb..da3ffbae 100644 --- a/backend/src/config/secret-bundle.ts +++ b/backend/src/config/secret-bundle.ts @@ -30,6 +30,8 @@ const MAX_LINE_BYTES = 16 * 1024; export interface SecretBundleConfig { secretsFile?: string; secretFiles?: Readonly>; + /** Accepted for callers that pass the raw process environment. */ + THT_SECRETS_FILE?: string; } function unavailable(): Error { return new Error("secret bundle is unavailable"); } @@ -89,12 +91,18 @@ export function loadSecretBundle(file: string): ReadonlyMap { /** Resolve a value from the bundle, with the pre-bundle *_SECRET_FILE fallback. */ export function secretValue(config: SecretBundleConfig, key: string): string | undefined { - if (config.secretsFile) { - const found = loadSecretBundle(config.secretsFile).get(key); + const bundlePath = config.secretsFile ?? config.THT_SECRETS_FILE; + if (bundlePath) { + const found = loadSecretBundle(bundlePath).get(key); if (found !== undefined) return found; } const legacyName = LEGACY_FILES[key]; - const legacyPath = legacyName ? config.secretFiles?.[legacyName] : undefined; + const legacyPath = legacyName + ? config.secretFiles?.[legacyName] ?? (() => { + const raw = (config as unknown as Record)[legacyName]; + return typeof raw === "string" ? raw : undefined; + })() + : undefined; if (!legacyPath) return undefined; const value = readSecure(legacyPath); if (!value || /\s/.test(value)) throw unavailable();