Presently, atticd's JWT secrets can be passed either in the config file or as env vars. systemd credentials are a nice way of plumbing secrets through system containers, but they very strongly want to be passed as files to be read from, rather than as env vars or spliced in to config files.
It's possible to hack around this with shell, but it's ugly:
[Service]
ExecStart=${pkgs.bash}/bin/bash -c 'ATTIC_SERVER_TOKEN_RS256_SECRET_BASE64="$(< $CREDENTIALS_DIRECTORY/attic-token-secret)" ${pkgs.attic-server}/bin/atticd --config ${atticd-config}'
LoadCredential=attic-token-secret
compared to an imagined result:
[Service]
ExecStart=${pkgs.attic-server}/bin/atticd --config ${atticd-config} --token-rs256-secret-file=$CREDENTIALS_DIRECTORY/attic-token-secret
LoadCredential=attic-token-secret
Presently, atticd's JWT secrets can be passed either in the config file or as env vars. systemd credentials are a nice way of plumbing secrets through system containers, but they very strongly want to be passed as files to be read from, rather than as env vars or spliced in to config files.
It's possible to hack around this with shell, but it's ugly:
compared to an imagined result: