feat(compose): use one secret bundle for local services

This commit is contained in:
2026-07-12 11:30:43 +02:00
parent 32a2b71687
commit 70a19f290d
15 changed files with 411 additions and 84 deletions
+5 -4
View File
@@ -3,10 +3,11 @@ set -eu
. /opt/thoth/secret-policy.sh
export PGPASSWORD=$(read_secret_file /run/secrets/vector_bootstrap_password vector_bootstrap_password)
migrator_password=$(read_secret_file /run/secrets/vector_migrator_password vector_migrator_password)
reader_password=$(read_secret_file /run/secrets/vector_reader_password vector_reader_password)
writer_password=$(read_secret_file /run/secrets/vector_writer_password vector_writer_password)
bundle=${THT_SECRETS_FILE:-/run/secrets/thothii.secrets}
export PGPASSWORD=$(read_bundle_secret "$bundle" THT_VECTOR_BOOTSTRAP_PASSWORD)
migrator_password=$(read_bundle_secret "$bundle" THT_VECTOR_MIGRATOR_PASSWORD)
reader_password=$(read_bundle_secret "$bundle" THT_VECTOR_READER_PASSWORD)
writer_password=$(read_bundle_secret "$bundle" THT_VECTOR_WRITER_PASSWORD)
psql --set=ON_ERROR_STOP=1 \
--set=migrator_user="$THT_VECTOR_MIGRATOR_USER" \