fix(deploy): close container final review
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
# Runtime secrets and private CA
|
||||
|
||||
Do not put secret values in this directory or in Git. For production, create files outside the
|
||||
repository and point the `*_SECRET_FILE` variables documented in the root README at them.
|
||||
|
||||
Compose mounts each file read-only beneath `/run/secrets`. The core process runs as UID 10001;
|
||||
the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally
|
||||
mounted read-only with mode `0444`; verify with:
|
||||
|
||||
```sh
|
||||
docker compose -f compose.yaml -f deploy/compose.production.yaml \
|
||||
--profile external run --rm core sh -c 'id && test -r /run/secrets/thoth_ca.pem'
|
||||
```
|
||||
|
||||
The CA file should contain only the public PEM certificate chain. API-key files should contain
|
||||
one value with no surrounding quotes.
|
||||
Reference in New Issue
Block a user