# Select this override only for an HTTPS Git remote. The separate CA mount keeps TLS validation # explicit; neither host-only source file nor its contents belongs in the base Compose contract. services: core: environment: GIT_CONFIG_COUNT: "2" GIT_CONFIG_KEY_0: credential.helper GIT_CONFIG_VALUE_0: store --file=/run/secrets/workspace-registry-git-credentials GIT_CONFIG_KEY_1: http.sslCAInfo GIT_CONFIG_VALUE_1: /run/secrets/workspace-registry-git-ca volumes: - ${THT_WORKSPACE_GIT_CREDENTIALS_FILE:?set THT_WORKSPACE_GIT_CREDENTIALS_FILE}:/run/secrets/workspace-registry-git-credentials:ro - ${THT_WORKSPACE_GIT_CA_FILE:?set THT_WORKSPACE_GIT_CA_FILE}:/run/secrets/workspace-registry-git-ca:ro