feat(config): load one validated secret bundle
This commit is contained in:
@@ -8,6 +8,8 @@ export interface AppConfig {
|
||||
settingsFile: string;
|
||||
dataRoot?: string;
|
||||
ollamaEnsureTimeoutMs: number;
|
||||
secretsFile?: string;
|
||||
secretFiles: Readonly<Record<string, string | undefined>>;
|
||||
modelApiKeyFile?: string;
|
||||
}
|
||||
export function loadConfig(env: Record<string, string | undefined>): AppConfig {
|
||||
@@ -27,6 +29,18 @@ export function loadConfig(env: Record<string, string | undefined>): AppConfig {
|
||||
)) {
|
||||
throw new Error("model credential configuration is invalid");
|
||||
}
|
||||
const secretsFile = env.THT_SECRETS_FILE;
|
||||
if (secretsFile !== undefined && (
|
||||
secretsFile.trim() !== secretsFile || secretsFile.length === 0 || secretsFile.includes("\0")
|
||||
|| !path.isAbsolute(secretsFile)
|
||||
)) throw new Error("secret bundle configuration is invalid");
|
||||
const secretFiles: Record<string, string | undefined> = {};
|
||||
for (const name of [
|
||||
"THT_MODEL_API_KEY_SECRET_FILE", "THT_DWH_API_KEY_SECRET_FILE", "THT_VEC_API_KEY_SECRET_FILE",
|
||||
"THT_VEC_WRITE_API_KEY_SECRET_FILE", "THT_CA_SECRET_FILE", "THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE",
|
||||
"THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE", "THT_VECTOR_READER_PASSWORD_SECRET_FILE",
|
||||
"THT_VECTOR_WRITER_PASSWORD_SECRET_FILE",
|
||||
]) secretFiles[name] = env[name];
|
||||
return {
|
||||
host: env.HOST ?? "127.0.0.1",
|
||||
port: Number(env.PORT ?? 8787),
|
||||
@@ -39,6 +53,8 @@ export function loadConfig(env: Record<string, string | undefined>): AppConfig {
|
||||
settingsFile: env.SETTINGS_FILE ?? "data/settings.json",
|
||||
dataRoot: env.THT_DATA_ROOT,
|
||||
ollamaEnsureTimeoutMs: Number(env.OLLAMA_ENSURE_TIMEOUT_MS ?? 60000),
|
||||
secretsFile,
|
||||
secretFiles,
|
||||
modelApiKeyFile,
|
||||
};
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user