sops secrets path changed

This commit is contained in:
2026-10-09 19:26:31 +03:00
parent 02927a26bb
commit a4984a6b37
5 changed files with 81 additions and 13 deletions
+9 -1
View File
@@ -92,7 +92,15 @@ in
# is the only source — and the container will refuse to start with
# WEBUI_SECRET_KEY="" (env.py:762 — SystemExit). The error message is
# the clear signal that the secret needs to be created.
environmentFiles = lib.optional (builtins.pathExists ./secrets/open-webui.env) "/run/secrets/open-webui-env";
# Path comes from the sops block below (`config.sops.secrets.<attr>.path`)
# rather than a hardcoded "/run/secrets/<attr>" — see invariant S1
# in docs/arch/invariants.md. Guards the sopsFile existence so the
# block is optional; the same predicate is what `sops.secrets` uses
# to decide whether to declare the attr at all, so `.path` is only
# read when the secret actually exists.
environmentFiles =
lib.optional (builtins.pathExists ./secrets/open-webui.env)
config.sops.secrets."open-webui-env".path;
volumes = [
"${panel}/data:/app/backend/data:rw"
];
+12 -3
View File
@@ -6,6 +6,15 @@
xlib,
...
}:
let
# Composite env file path shared by the generator
# (remnawave-env.service below) and the container's `environmentFiles`.
# Lifting to a single binding prevents the two copies from drifting
# apart in future edits — see invariant S1 in docs/arch/invariants.md.
# Note: this is NOT a sops materialization (it's written by a oneshot),
# so `config.sops.secrets.<...>.path` is not the right primitive here.
envFile = "/run/secrets/remnawave-env";
in
{
# Runtime
virtualisation.podman = {
@@ -58,7 +67,7 @@
# "WEBHOOK_URL" = "https://your-webhook-url.com/endpoint";
};
environmentFiles = [
"/run/secrets/remnawave-env"
envFile
];
ports = [
"3003:3003/tcp"
@@ -126,14 +135,14 @@
User = "root";
};
script = ''
cat > /run/secrets/remnawave-env <<EOF
cat > ${envFile} <<EOF
DATABASE_URL=$(cat ${config.sops.secrets.DATABASE_URL.path})
DATABASE_PASSWORD=$(cat ${config.sops.secrets.DATABASE_PASSWORD.path})
JWT_AUTH_SECRET=$(cat ${config.sops.secrets.JWT_AUTH_SECRET.path})
JWT_API_TOKENS_SECRET=$(cat ${config.sops.secrets.JWT_API_TOKENS_SECRET.path})
WEBHOOK_SECRET_HEADER=$(cat ${config.sops.secrets.WEBHOOK_SECRET_HEADER.path})
EOF
chmod 600 /run/secrets/remnawave-env
chmod 600 ${envFile}
'';
wantedBy = [ "multi-user.target" ];
};
+3 -1
View File
@@ -58,7 +58,9 @@ in
"NOTIFY_DAYS_BEFORE" = "7";
"TZ" = "Europe/Moscow";
};
environmentFiles = [ "/run/secrets/tape-rotation-env" ];
# Path resolved from the sops block at the bottom of this file —
# see invariant S1 in docs/arch/invariants.md.
environmentFiles = [ config.sops.secrets."tape-rotation-env".path ];
volumes = [
"${panel}/db:/data:rw"
"${panel}/uploads:/app/uploads:rw"