feat(compose): use one secret bundle for local services

This commit is contained in:
2026-07-12 11:30:43 +02:00
parent 32a2b71687
commit 70a19f290d
15 changed files with 411 additions and 84 deletions
+4 -11
View File
@@ -1,21 +1,14 @@
services:
preprocess-evidence:
environment:
THT_VECTOR_READER_PASSWORD_FILE: /run/secrets/vector_reader_password
THT_VECTOR_WRITER_PASSWORD_FILE: /run/secrets/vector_writer_password
secrets: [vector_reader_password, vector_writer_password]
THT_SECRETS_FILE: /run/secrets/thothii.secrets
secrets: [{source: thothii_secrets, target: thothii.secrets}]
depends_on:
vector-migrate: {condition: service_completed_successfully}
preprocess-dwh:
environment:
THT_VECTOR_READER_PASSWORD_FILE: /run/secrets/vector_reader_password
secrets: [vector_reader_password]
THT_SECRETS_FILE: /run/secrets/thothii.secrets
secrets: [{source: thothii_secrets, target: thothii.secrets}]
depends_on:
vector-migrate: {condition: service_completed_successfully}
secrets:
vector_reader_password:
file: ${THT_VECTOR_READER_PASSWORD_SECRET_FILE:?set THT_VECTOR_READER_PASSWORD_SECRET_FILE}
vector_writer_password:
file: ${THT_VECTOR_WRITER_PASSWORD_SECRET_FILE:?set THT_VECTOR_WRITER_PASSWORD_SECRET_FILE}