fix: use standard secret file names (db_password.txt, encryption_key.txt)
Revert workaround names (db_pw.txt, enc_key.txt) — fresh deploys only have standard names. Default paths now match what docker compose mounts from secrets/.
This commit is contained in:
@@ -18,7 +18,7 @@ class Settings(BaseSettings):
|
||||
# to override whatever password is embedded in DATABASE_URL. Keeps
|
||||
# DB credentials out of plain env vars, consistent with how JWT keys
|
||||
# are already handled.
|
||||
DB_PASSWORD_FILE: str = "/run/secrets/db_pw.txt"
|
||||
DB_PASSWORD_FILE: str = "/run/secrets/db_password.txt"
|
||||
|
||||
# JWT
|
||||
JWT_PRIVATE_KEY_PATH: str = "/run/secrets/jwt_private.pem"
|
||||
@@ -30,7 +30,7 @@ class Settings(BaseSettings):
|
||||
# Encryption
|
||||
ENCRYPTION_KEY: str = ""
|
||||
# If set, ENCRYPTION_KEY is read from this file (Docker secret) instead.
|
||||
ENCRYPTION_KEY_FILE: str = "/run/secrets/enc_key.txt"
|
||||
ENCRYPTION_KEY_FILE: str = "/run/secrets/encryption_key.txt"
|
||||
|
||||
# Redis (shared cache across backend-api / backend-scheduler processes).
|
||||
# Optional: if unreachable, callers fall back to per-process in-memory
|
||||
|
||||
Reference in New Issue
Block a user