Skip to content

DRU-708 -- Read deployment secrets from files - #65

Merged
czpython merged 1 commit into
mainfrom
paulo/dru-708-read-drukbox-deployment-secrets-from-files
Oct 3, 2026
Merged

czpython merged 1 commit into
mainfrom
paulo/dru-708-read-drukbox-deployment-secrets-from-files

Conversation

@czpython

@czpython czpython commented Oct 3, 2026

Copy link
Copy Markdown
Owner

A process reads a setting from a file in /run/secrets when that directory exists. The file name is the variable name, for example /run/secrets/DATABASE_URL. Compose file secrets mount there, so a deployment can keep its secrets out of docker inspect and out of the environment that subprocesses inherit.

  • The core, exe.dev, Hetzner, Exoscale, and Tailscale settings read the directory. An environment variable or a .env entry still wins over a file.
  • The directory is used only when it exists, because pydantic-settings warns on every load when it is missing.
  • The provider settings set hide_input_in_errors, like the core settings. A missing Tailscale value no longer prints TAILSCALE_OAUTH_CLIENT_SECRET in the startup error.
  • docs/deploy.md has a new "Secret files" section: file names, precedence, a Compose example, and file ownership for the image's UID 1001.

@czpython czpython changed the title Read deployment secrets from files DRU-708 -- Read deployment secrets from files Oct 3, 2026
@czpython
czpython force-pushed the paulo/dru-708-read-drukbox-deployment-secrets-from-files branch from ae7cc32 to a6f7939 Compare October 3, 2026 13:53
A process reads a setting from /run/secrets/<NAME> when that directory
exists, so a deployment can keep secrets out of the environment. The
provider settings also hide their input in startup errors.
@czpython
czpython force-pushed the paulo/dru-708-read-drukbox-deployment-secrets-from-files branch from a6f7939 to d138fac Compare October 3, 2026 13:57
@czpython
czpython merged commit 17ae9d2 into main Oct 3, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant