deploy/gen_env.sh: generate .env with openssl secrets
Builds deploy/.env from .env.example, generating SECRET_KEY and both database passwords with openssl (base64/hex only, so nothing needs quoting in the env file or the compose parser). Derives TS_HOSTNAME and ALLOWED_HOSTS from the tailnet hostname, optionally sets CORS_ALLOWED_ORIGINS/CSRF_TRUSTED_ORIGINS for split deployments, forces DEBUG=False and writes the file with mode 600. Modes: --no-prompt (defaults only), --update (refresh hostnames/auth key while keeping the existing secrets, reading the stored FQDN from ALLOWED_HOSTS), --force (rotate everything, with the SECRET_KEY warning in the docs). Refuses to overwrite an existing file otherwise. Verified: all modes, updated FQDN preservation, mode 600, and docker compose config accepting the generated file.
This commit is contained in:
@@ -39,7 +39,8 @@ Project constraints (do not regress):
|
||||
serve.*.tailnet.json + compose.tailnet*.yml are the same stacks without
|
||||
AllowFunnel (tailnet-only, no public exposure). Images are pushed to the
|
||||
Gitea registry with deploy/push_*.sh (multi-arch, :latest + :sha, GIT_HASH
|
||||
baked in for the version pill).
|
||||
baked in for the version pill); deploy/gen_env.sh generates .env with
|
||||
openssl secrets (--update keeps SECRET_KEY, --force rotates it).
|
||||
- Security/permission tests live in backend/apps/core/tests and need a
|
||||
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';
|
||||
|
||||
|
||||
Reference in New Issue
Block a user