DRU-735 -- Keep secrets out of druks.toml - #823
Merged
Merged
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
czpython
force-pushed
the
paulo/dru-735-keep-secrets-out-of-drukstoml
branch
from
October 4, 2026 13:45
d4fa15e to
60b8204
Compare
czpython
force-pushed
the
paulo/dru-735-keep-secrets-out-of-drukstoml
branch
from
October 4, 2026 14:36
60b8204 to
57936cf
Compare
czpython
force-pushed
the
paulo/dru-735-keep-secrets-out-of-drukstoml
branch
from
October 4, 2026 14:46
57936cf to
68b67ba
Compare
czpython
force-pushed
the
paulo/dru-735-keep-secrets-out-of-drukstoml
branch
from
October 4, 2026 15:06
68b67ba to
c149a1f
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
druks.tomlholds no secret. Druks takes each secret from an environment variable, and the installer keeps the secrets of an installation in the last section of.env.druks.tomlsetstimezoneand the tables. The environment sets the settings that carry an alias. A secret (secrets_key,database_url,redis_url,sandbox.service_token,sandbox.browser_login_proxy) comes from its variable, such asDRUKS_SANDBOX_SERVICE_TOKEN. Each one is aSecretStr, sorepr(settings)shows none.DRUKS_SECRETS_DIRnames a directory, Druks also reads a secret from the file that has its key path as its name, such assandbox.service_token. This is for a platform that delivers secrets as files. The installer does not use it.redis_urlis a secret, because the address can carry the Redis password. Its variable keeps the nameDRUKS_REDIS_URL.druks.tomlholds a secret, or when a top-level key ofdruks.tomlnames a setting of the environment. Before this change, a top-leveldata_dirin the file replaced the container path that Compose injects.druks setupgenerates the Postgres password, the vault key, the Drukbox key, and the sandbox token into the last section of.env. It keeps each line of that section on a later run, so an operator adds a provider secret there as a line. The local shape gets a generated sandbox token in place ofdev-token, and it asks the operator for no secret.druks.tomlholds.druks setupmoves it to.envand removes the key, so--setof a known secret also lands in.env. The[secrets]table goes away. A variable that is indruks.tomland in the secrets section is a named gap..envis state. It is the only copy of the generated secrets.druks setupreplaces it in one step, and writes it before it removes a moved secret fromdruks.toml. A deleted.envno longer comes back with the same secrets..env:DRUKS_SECRETS_KEYandDRUKS_DATABASE_URL..env.exampleloses the unusedSLACK_SIGNING_SECRET.The Compose files do not change.