fix: use standard secret file names (db_password.txt, encryption_key.txt)
Revert workaround names (db_pw.txt, enc_key.txt) — fresh deploys only have standard names. Default paths now match what docker compose mounts from secrets/.
This commit is contained in:
@@ -18,7 +18,7 @@ class Settings(BaseSettings):
|
|||||||
# to override whatever password is embedded in DATABASE_URL. Keeps
|
# to override whatever password is embedded in DATABASE_URL. Keeps
|
||||||
# DB credentials out of plain env vars, consistent with how JWT keys
|
# DB credentials out of plain env vars, consistent with how JWT keys
|
||||||
# are already handled.
|
# are already handled.
|
||||||
DB_PASSWORD_FILE: str = "/run/secrets/db_pw.txt"
|
DB_PASSWORD_FILE: str = "/run/secrets/db_password.txt"
|
||||||
|
|
||||||
# JWT
|
# JWT
|
||||||
JWT_PRIVATE_KEY_PATH: str = "/run/secrets/jwt_private.pem"
|
JWT_PRIVATE_KEY_PATH: str = "/run/secrets/jwt_private.pem"
|
||||||
@@ -30,7 +30,7 @@ class Settings(BaseSettings):
|
|||||||
# Encryption
|
# Encryption
|
||||||
ENCRYPTION_KEY: str = ""
|
ENCRYPTION_KEY: str = ""
|
||||||
# If set, ENCRYPTION_KEY is read from this file (Docker secret) instead.
|
# If set, ENCRYPTION_KEY is read from this file (Docker secret) instead.
|
||||||
ENCRYPTION_KEY_FILE: str = "/run/secrets/enc_key.txt"
|
ENCRYPTION_KEY_FILE: str = "/run/secrets/encryption_key.txt"
|
||||||
|
|
||||||
# Redis (shared cache across backend-api / backend-scheduler processes).
|
# Redis (shared cache across backend-api / backend-scheduler processes).
|
||||||
# Optional: if unreachable, callers fall back to per-process in-memory
|
# Optional: if unreachable, callers fall back to per-process in-memory
|
||||||
|
|||||||
Reference in New Issue
Block a user