Files
ThothII/deploy/secrets/README.md
T

755 B

Runtime secrets and private CA

Do not put secret values in this directory or in Git. For production, create files outside the repository and point the *_SECRET_FILE variables documented in the root README at them.

Compose mounts each file read-only beneath /run/secrets. The core process runs as UID 10001; the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally mounted read-only with mode 0444; verify with:

docker compose -f compose.yaml -f deploy/compose.production.yaml \
  --profile external run --rm core sh -c 'id && test -r /run/secrets/thoth_ca.pem'

The CA file should contain only the public PEM certificate chain. API-key files should contain one value with no surrounding quotes.