Skip to content

atticd: Allow reading JWT secrets from named file #331

Description

@sepointon

Presently, atticd's JWT secrets can be passed either in the config file or as env vars. systemd credentials are a nice way of plumbing secrets through system containers, but they very strongly want to be passed as files to be read from, rather than as env vars or spliced in to config files.

It's possible to hack around this with shell, but it's ugly:

[Service]
ExecStart=${pkgs.bash}/bin/bash -c 'ATTIC_SERVER_TOKEN_RS256_SECRET_BASE64="$(< $CREDENTIALS_DIRECTORY/attic-token-secret)" ${pkgs.attic-server}/bin/atticd --config ${atticd-config}'
LoadCredential=attic-token-secret

compared to an imagined result:

[Service]
ExecStart=${pkgs.attic-server}/bin/atticd --config ${atticd-config} --token-rs256-secret-file=$CREDENTIALS_DIRECTORY/attic-token-secret
LoadCredential=attic-token-secret

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions