Files
ThothII/deploy/secrets/README.md
T

2.2 KiB

Runtime secrets and private CA

Do not put secret values in this directory or in Git. For production, create files outside the repository and point the *_SECRET_FILE variables documented in the root README at them.

Compose mounts each file read-only beneath /run/secrets. The core process runs as UID 10001; the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally mounted read-only with mode 0444; verify with:

docker compose -f compose.yaml -f deploy/compose.production.yaml \
  --profile external run --rm core sh -c 'id && test -r /run/secrets/thoth_ca.pem'

The CA file should contain only the public PEM certificate chain. API-key files should contain one value with no surrounding quotes.

Rotating the initialized local-vector bootstrap password

Replacing THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE or changing its contents does not rotate an initialized PostgreSQL cluster. Use the supported workflow against the running local-vector project:

./scripts/vector-rotate-bootstrap-password.sh \
  /absolute/path/to/current-bootstrap-secret \
  /absolute/path/to/staged-new-bootstrap-secret

The command authenticates using the current file, changes only the authenticated bootstrap role, verifies a new login, and only then atomically replaces the current deployment secret file. If old authentication or new-login verification fails, it exits without changing the deployment file; verification failure also attempts to restore the old database password over the still-open authenticated connection. After success, run the printed vector-reconcile/migration/core command.

THT_VECTOR_BOOTSTRAP_USER is authoritative for database initialization, reconciliation, and rotation; non-default bootstrap role names are supported. Bootstrap, migrator, reader, and writer secret files must be non-empty and contain no whitespace (including trailing newlines). Rotation rejects invalid files before contacting PostgreSQL or staging a deployment-file replacement.

Keep the staged new file on the same trusted host, mode 0600, and retain a secure backup until the post-rotation reconciliation and application health checks pass.