docs(secrets): document Infisical secrets read by this repo
Add/standardize a ## Secrets section listing the vault_* keys pulled from Infisical at deploy time, grouped by folder. Part of a fleet-wide README secrets-documentation sweep. Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
ec46d21676
commit
2b5b56c7ed
@@ -141,6 +141,25 @@ UI to generate a per-user token. Use it as the bearer for either:
|
||||
`Wait for Dawarich to be healthy` task is `ignore_errors: true` for the same reason.
|
||||
- **SSO button is POST, not GET.** The signin page renders a `<form method="post" action="/users/auth/openid_connect">`; the button submits with a Rails CSRF token. `GET /users/auth/openid_connect` returns 404 — that's CSRF working, not a routing bug.
|
||||
|
||||
## Secrets
|
||||
|
||||
Pulled from Infisical at deploy time (`infisical.vault.read_secrets` in `site.yml`):
|
||||
|
||||
**`/dawarich/`**
|
||||
- `vault_dawarich_db_password` — PostGIS DB password
|
||||
- `vault_dawarich_secret_key_base` — Rails `SECRET_KEY_BASE`
|
||||
- `vault_dawarich_otp_primary_key` — OTP/attr-encryption primary key
|
||||
- `vault_dawarich_otp_deterministic_key` — OTP deterministic-encryption key
|
||||
- `vault_dawarich_otp_salt` — OTP key-derivation salt
|
||||
|
||||
**`/oidc/`**
|
||||
- `vault_dawarich_oidc_client_id` — Authentik OIDC client ID
|
||||
- `vault_dawarich_oidc_client_secret` — Authentik OIDC client secret
|
||||
|
||||
**`/shared/`**
|
||||
- `vault_watchtower_gotify_url` — Watchtower Gotify notification URL
|
||||
- `vault_watchtower_api_token` — Watchtower HTTP API trigger token
|
||||
|
||||
## Notes
|
||||
|
||||
- Postgres data lives at `/opt/dawarich/postgres` (uid 70, alpine `postgres`
|
||||
|
||||
Reference in New Issue
Block a user