deploy: isolate git and connector secrets

This commit is contained in:
2026-08-04 15:04:39 +02:00
parent ff271d3cce
commit b5071f1494
7 changed files with 189 additions and 3 deletions
+8 -2
View File
@@ -1,6 +1,7 @@
# Copy these non-secret registry settings into the installation environment.
# Create the referenced credential, CA, SSH-key, and known-hosts files locally with restrictive
# permissions. Their contents are never committed, emitted by the API, or stored in the registry.
# Select at most one Git transport override and only the connector-secret entries whose matching
# THT_WS_*_FILE bindings are declared. Every host path below must be absolute and normalized.
# Their contents are never committed, emitted by the API, or stored in the registry.
THT_WORKSPACE_REGISTRY_ROOT=/data/workspace-registry
THT_WORKSPACE_GIT_BRANCH=main
THT_WORKSPACE_INSTALLATION_ID=local
@@ -13,3 +14,8 @@ THT_WORKSPACE_GIT_AUTHOR_EMAIL=thoth-workspace-registry@localhost
# THT_WORKSPACE_GIT_CA_FILE=/absolute/path/to/git-ca.pem
# THT_WORKSPACE_GIT_SSH_KEY_FILE=/absolute/path/to/git-ssh-key
# THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=/absolute/path/to/git-known-hosts
# Host-only connector sources consumed only by deploy/compose.connector-secrets.yaml. The matching
# THT_WS_*_FILE values belong in the separate workspace bindings env file and target /run/secrets.
# THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE=/absolute/path/to/psd-clinical-dwh-password
# THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE=/absolute/path/to/psd-clinical-vector-password