25 lines
784 B
Bash
Executable File
25 lines
784 B
Bash
Executable File
#!/bin/sh
|
|
|
|
validate_secret_file() {
|
|
secret_path=$1
|
|
secret_name=$2
|
|
if [ ! -f "$secret_path" ] || [ ! -r "$secret_path" ] || [ ! -s "$secret_path" ]; then
|
|
echo "$secret_name must be a readable, non-empty regular file" >&2
|
|
return 2
|
|
fi
|
|
if LC_ALL=C grep -q '[[:space:]]' "$secret_path"; then
|
|
echo "$secret_name must contain no whitespace" >&2
|
|
return 2
|
|
fi
|
|
mode=$(stat -c '%a' "$secret_path" 2>/dev/null || stat -f '%Lp' "$secret_path" 2>/dev/null) || return 2
|
|
case "$secret_path:$mode" in
|
|
/run/secrets/*:444|/run/secrets/*:400|/run/secrets/*:600|*:600|*:400) ;;
|
|
*) echo "$secret_name must have mode 0600 or stricter (Docker secrets may be 0444)" >&2; return 2 ;;
|
|
esac
|
|
}
|
|
|
|
read_secret_file() {
|
|
validate_secret_file "$1" "$2" || return
|
|
cat "$1"
|
|
}
|