deploy: isolate git and connector secrets
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
# Selected direct PostgreSQL/pgvector connector secrets. Each target must match a corresponding
|
||||
# THT_WS_*_FILE=/run/secrets/<target> binding; source paths are host-only operator configuration.
|
||||
services:
|
||||
core:
|
||||
secrets:
|
||||
- source: psd_clinical_dwh_password
|
||||
target: psd-clinical-dwh-password
|
||||
- source: psd_clinical_vector_password
|
||||
target: psd-clinical-vector-password
|
||||
|
||||
secrets:
|
||||
psd_clinical_dwh_password:
|
||||
file: ${THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE:?set THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE}
|
||||
psd_clinical_vector_password:
|
||||
file: ${THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE:?set THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE}
|
||||
@@ -0,0 +1,13 @@
|
||||
# Select this override only for an HTTPS Git remote. The separate CA mount keeps TLS validation
|
||||
# explicit; neither host-only source file nor its contents belongs in the base Compose contract.
|
||||
services:
|
||||
core:
|
||||
environment:
|
||||
GIT_CONFIG_COUNT: "2"
|
||||
GIT_CONFIG_KEY_0: credential.helper
|
||||
GIT_CONFIG_VALUE_0: store --file=/run/secrets/workspace-registry-git-credentials
|
||||
GIT_CONFIG_KEY_1: http.sslCAInfo
|
||||
GIT_CONFIG_VALUE_1: /run/secrets/workspace-registry-git-ca
|
||||
volumes:
|
||||
- ${THT_WORKSPACE_GIT_CREDENTIALS_FILE:?set THT_WORKSPACE_GIT_CREDENTIALS_FILE}:/run/secrets/workspace-registry-git-credentials:ro
|
||||
- ${THT_WORKSPACE_GIT_CA_FILE:?set THT_WORKSPACE_GIT_CA_FILE}:/run/secrets/workspace-registry-git-ca:ro
|
||||
@@ -0,0 +1,9 @@
|
||||
# Select this override only for an SSH Git remote. The host-only source files must be absolute,
|
||||
# normalized paths; strict host-key checking is mandatory for registry pull and publish.
|
||||
services:
|
||||
core:
|
||||
environment:
|
||||
GIT_SSH_COMMAND: ssh -i /run/secrets/workspace-registry-git-ssh-key -o IdentitiesOnly=yes -o StrictHostKeyChecking=yes -o UserKnownHostsFile=/run/secrets/workspace-registry-git-known-hosts
|
||||
volumes:
|
||||
- ${THT_WORKSPACE_GIT_SSH_KEY_FILE:?set THT_WORKSPACE_GIT_SSH_KEY_FILE}:/run/secrets/workspace-registry-git-ssh-key:ro
|
||||
- ${THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE:?set THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE}:/run/secrets/workspace-registry-git-known-hosts:ro
|
||||
@@ -1,6 +1,7 @@
|
||||
# Copy these non-secret registry settings into the installation environment.
|
||||
# Create the referenced credential, CA, SSH-key, and known-hosts files locally with restrictive
|
||||
# permissions. Their contents are never committed, emitted by the API, or stored in the registry.
|
||||
# Select at most one Git transport override and only the connector-secret entries whose matching
|
||||
# THT_WS_*_FILE bindings are declared. Every host path below must be absolute and normalized.
|
||||
# Their contents are never committed, emitted by the API, or stored in the registry.
|
||||
THT_WORKSPACE_REGISTRY_ROOT=/data/workspace-registry
|
||||
THT_WORKSPACE_GIT_BRANCH=main
|
||||
THT_WORKSPACE_INSTALLATION_ID=local
|
||||
@@ -13,3 +14,8 @@ THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-workspace-registry@localhost
|
||||
# THT_WORKSPACE_GIT_CA_FILE=/absolute/path/to/git-ca.pem
|
||||
# THT_WORKSPACE_GIT_SSH_KEY_FILE=/absolute/path/to/git-ssh-key
|
||||
# THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=/absolute/path/to/git-known-hosts
|
||||
|
||||
# Host-only connector sources consumed only by deploy/compose.connector-secrets.yaml. The matching
|
||||
# THT_WS_*_FILE values belong in the separate workspace bindings env file and target /run/secrets.
|
||||
# THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE=/absolute/path/to/psd-clinical-dwh-password
|
||||
# THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE=/absolute/path/to/psd-clinical-vector-password
|
||||
|
||||
Reference in New Issue
Block a user