Skip to content

DRU-735 -- Keep secrets out of druks.toml - #823

Merged
czpython merged 1 commit into
mainfrom
paulo/dru-735-keep-secrets-out-of-drukstoml
Oct 4, 2026
Merged

czpython merged 1 commit into
mainfrom
paulo/dru-735-keep-secrets-out-of-drukstoml

Conversation

@czpython

@czpython czpython commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What changed

druks.toml holds no secret. Druks takes each secret from an environment variable, and the installer keeps the secrets of an installation in the last section of .env.

  • Settings. Each setting has one source. druks.toml sets timezone and the tables. The environment sets the settings that carry an alias. A secret (secrets_key, database_url, redis_url, sandbox.service_token, sandbox.browser_login_proxy) comes from its variable, such as DRUKS_SANDBOX_SERVICE_TOKEN. Each one is a SecretStr, so repr(settings) shows none.
  • Secret files. When DRUKS_SECRETS_DIR names a directory, Druks also reads a secret from the file that has its key path as its name, such as sandbox.service_token. This is for a platform that delivers secrets as files. The installer does not use it.
  • Redis. redis_url is a secret, because the address can carry the Redis password. Its variable keeps the name DRUKS_REDIS_URL.
  • Refusals. Druks does not start when a secret is in the environment and in a file, when druks.toml holds a secret, or when a top-level key of druks.toml names a setting of the environment. Before this change, a top-level data_dir in the file replaced the container path that Compose injects.
  • Installer. druks setup generates the Postgres password, the vault key, the Drukbox key, and the sandbox token into the last section of .env. It keeps each line of that section on a later run, so an operator adds a provider secret there as a line. The local shape gets a generated sandbox token in place of dev-token, and it asks the operator for no secret.
  • A secret that druks.toml holds. druks setup moves it to .env and removes the key, so --set of a known secret also lands in .env. The [secrets] table goes away. A variable that is in druks.toml and in the secrets section is a named gap.
  • .env is state. It is the only copy of the generated secrets. druks setup replaces it in one step, and writes it before it removes a moved secret from druks.toml. A deleted .env no longer comes back with the same secrets.
  • Development. A host-run server keeps its secrets in .env: DRUKS_SECRETS_KEY and DRUKS_DATABASE_URL. .env.example loses the unused SLACK_SIGNING_SECRET.

The Compose files do not change.

@mintlify

mintlify Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
druks 🟢 Ready View Preview Oct 4, 2026, 3:06 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@czpython
czpython force-pushed the paulo/dru-735-keep-secrets-out-of-drukstoml branch from 68b67ba to c149a1f Compare October 4, 2026 15:06
@czpython
czpython merged commit 07d9c72 into main Oct 4, 2026
5 checks passed
@czpython
czpython deleted the paulo/dru-735-keep-secrets-out-of-drukstoml branch October 4, 2026 15:09

This branch was successfully deployed

1 active deployment
staging - docs — c149a1f8 Deployed Oct 4, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant