fix(deploy): isolate local vector compose secrets
This commit is contained in:
@@ -23,7 +23,8 @@ THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE="$tmp/bootstrap" \
|
||||
THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE="$tmp/migrator" \
|
||||
THT_VECTOR_READER_PASSWORD_SECRET_FILE="$tmp/local_reader" \
|
||||
THT_VECTOR_WRITER_PASSWORD_SECRET_FILE="$tmp/local_writer" \
|
||||
docker compose --profile local-vector config >"$tmp/local-vector.yaml"
|
||||
docker compose -f compose.yaml -f deploy/compose.local-vector.yaml \
|
||||
--profile local-vector config >"$tmp/local-vector.yaml"
|
||||
grep -q 'THT_VECTOR_READER_PASSWORD_FILE: /run/secrets/vector_reader_password' "$tmp/local-vector.yaml"
|
||||
grep -q 'THT_VECTOR_WRITER_PASSWORD_FILE: /run/secrets/vector_writer_password' "$tmp/local-vector.yaml"
|
||||
if grep -q 'contract-local_' "$tmp/local-vector.yaml"; then
|
||||
@@ -48,6 +49,10 @@ grep -q 'AUTH_MODE: upstream' "$tmp/production.yaml"
|
||||
grep -q 'THOTH_PUBLIC_EXPOSURE: "true"' "$tmp/production.yaml"
|
||||
grep -q 'target: thoth_ca.pem' "$tmp/production.yaml"
|
||||
grep -q 'THT_DWH_API_KEY_FILE: /run/secrets/dwh_api_key' "$tmp/production.yaml"
|
||||
if grep -q 'THT_VECTOR_READER_PASSWORD_FILE\|THT_VECTOR_WRITER_PASSWORD_FILE\|target: vector_reader_password\|target: vector_writer_password' "$tmp/production.yaml"; then
|
||||
echo "production external config contains local direct vector secrets" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if awk '/^FROM / && $2 !~ /@sha256:/ { found=1 } END { exit !found }' \
|
||||
docker/core.Dockerfile docker/frontend.Dockerfile; then
|
||||
|
||||
Reference in New Issue
Block a user