deploy/gen_env.sh: generate .env with openssl secrets

Builds deploy/.env from .env.example, generating SECRET_KEY and both
database passwords with openssl (base64/hex only, so nothing needs quoting
in the env file or the compose parser). Derives TS_HOSTNAME and
ALLOWED_HOSTS from the tailnet hostname, optionally sets
CORS_ALLOWED_ORIGINS/CSRF_TRUSTED_ORIGINS for split deployments, forces
DEBUG=False and writes the file with mode 600.

Modes: --no-prompt (defaults only), --update (refresh hostnames/auth key
while keeping the existing secrets, reading the stored FQDN from
ALLOWED_HOSTS), --force (rotate everything, with the SECRET_KEY warning in
the docs). Refuses to overwrite an existing file otherwise.

Verified: all modes, updated FQDN preservation, mode 600, and
docker compose config accepting the generated file.
This commit is contained in:
2026-09-18 12:46:56 -05:00
parent 30b1a1a4b0
commit 93cce6b9fd
3 changed files with 168 additions and 2 deletions
+2 -1
View File
@@ -39,7 +39,8 @@ Project constraints (do not regress):
serve.*.tailnet.json + compose.tailnet*.yml are the same stacks without
AllowFunnel (tailnet-only, no public exposure). Images are pushed to the
Gitea registry with deploy/push_*.sh (multi-arch, :latest + :sha, GIT_HASH
baked in for the version pill).
baked in for the version pill); deploy/gen_env.sh generates .env with
openssl secrets (--update keeps SECRET_KEY, --force rotates it).
- Security/permission tests live in backend/apps/core/tests and need a
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';