2.2 KiB
Runtime secrets and private CA
Do not put secret values in this directory or in Git. For production, create files outside the
repository and point the *_SECRET_FILE variables documented in the root README at them.
Compose mounts each file read-only beneath /run/secrets. The core process runs as UID 10001;
the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally
mounted read-only with mode 0444; verify with:
docker compose -f compose.yaml -f deploy/compose.production.yaml \
--profile external run --rm core sh -c 'id && test -r /run/secrets/thoth_ca.pem'
The CA file should contain only the public PEM certificate chain. API-key files should contain one value with no surrounding quotes.
Rotating the initialized local-vector bootstrap password
Replacing THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE or changing its contents does not rotate
an initialized PostgreSQL cluster. Use the supported workflow against the running local-vector
project:
./scripts/vector-rotate-bootstrap-password.sh \
/absolute/path/to/current-bootstrap-secret \
/absolute/path/to/staged-new-bootstrap-secret
The command authenticates using the current file, changes only the authenticated bootstrap role,
verifies a new login, and only then atomically replaces the current deployment secret file. If old
authentication or new-login verification fails, it exits without changing the deployment file;
verification failure also attempts to restore the old database password over the still-open
authenticated connection. After success, run the printed vector-reconcile/migration/core command.
THT_VECTOR_BOOTSTRAP_USER is authoritative for database initialization, reconciliation, and
rotation; non-default bootstrap role names are supported. Bootstrap, migrator, reader, and writer
secret files must be non-empty and contain no whitespace (including trailing newlines). Rotation
rejects invalid files before contacting PostgreSQL or staging a deployment-file replacement.
Keep the staged new file on the same trusted host, mode 0600, and retain a secure backup until the
post-rotation reconciliation and application health checks pass.