fix(traefik): migrate KEEPALIVED_PASSWORD to Pattern C (manifest-driven), stop committing traefik.env #21

Merged
AVB merged 6 commits from migrate-traefik-keepalived-secret into main 2026-09-11 22:52:35 -07:00
Showing only changes of commit 201d8418ee - Show all commits
+15 -12
View File
@@ -1,22 +1,22 @@
# ───────────────────────────────────────────────────────────────────────────── # ─────────────────────────────────────────────────────────────────────────
# secrets-map.yaml — DATA-ONLY manifest for deploy/provision-stack.py # secrets-map.yaml — DATA-ONLY manifest for deploy/provision-stack.py
# #
# RULES: # RULES:
# - This file contains NO code, NO shell, NO secret values — only names. # - This file contains NO code, NO shell, NO secret values — only names.
# - Each stack entry declares: # - Each stack entry declares:
# env_template: repo path of the FULL env-file template (tracked). # env_template: repo path of the FULL env-file template (tracked).
# The template is authoritative: the COMPLETE env file is # The template is authoritative: the COMPLETE env file is
# rendered from it on every provisioning run. Nothing is # rendered from it on every provisioning run. Nothing is
# line-edited in place, so keys can never silently go # line-edited in place, so keys can never silently go
# missing. # missing.
# env_dest: host path (relative to /volume1/docker/compose-files/) # env_dest: host path (relative to /volume1/docker/compose-files/)
# the rendered env file is shipped to. Rendered file # the rendered env file is shipped to. Rendered file
# exists ONLY on the host — never committed to git. # exists ONLY on the host — never committed to git.
# docker_secrets: map of docker-swarm-secret-name -> CI ENV VAR NAME # docker_secrets: map of docker-swarm-secret-name -> CI ENV VAR NAME
# (Pattern C). The env var must be declared via # (Pattern C). The env var must be declared via
# from_secret: in .woodpecker/deploy.yml's # from_secret: in .woodpecker/deploy.yml's
# provision-secrets step (Woodpecker v3 requires explicit # provision-secrets step (Woodpecker v3 requires explicit
# per-secret declaration; there is no expose-all). # per-secret declaration; there is no expose-all).
# #
# ADDING A NEW SECRET (3 small steps, no shell edits): # ADDING A NEW SECRET (3 small steps, no shell edits):
# 1. Add the secret value in Woodpecker UI (repo Settings -> Secrets). # 1. Add the secret value in Woodpecker UI (repo Settings -> Secrets).
@@ -27,7 +27,7 @@
# #
# Stacks not listed here fall through to deploy.yml's legacy case-entries # Stacks not listed here fall through to deploy.yml's legacy case-entries
# untouched. Migration is deliberately one stack per PR. # untouched. Migration is deliberately one stack per PR.
# ───────────────────────────────────────────────────────────────────────────── # ─────────────────────────────────────────────────────────────────────────
stacks: stacks:
ai: ai:
env_template: ai/ai.env.template env_template: ai/ai.env.template
@@ -36,3 +36,6 @@ stacks:
flowagent_azure_client_id: FLOWAGENT_AZURE_CLIENT_ID flowagent_azure_client_id: FLOWAGENT_AZURE_CLIENT_ID
flowagent_azure_tenant_id: FLOWAGENT_AZURE_TENANT_ID flowagent_azure_tenant_id: FLOWAGENT_AZURE_TENANT_ID
flowagent_azure_client_secret: FLOWAGENT_AZURE_CLIENT_SECRET flowagent_azure_client_secret: FLOWAGENT_AZURE_CLIENT_SECRET
traefik:
env_template: traefik/traefik.env.template
env_dest: traefik/traefik.env