feat: ship image config that reads signing_key from the environment
The runtime stage now copies config.docker.yml, which sets only signing_key (from PIXA_SIGNING_KEY), state_dir, and port. This drops the public placeholder key and the baked-in allowlist from the image, matching how upaas configures apps: environment variables and mounts, no injected config file. Model: opus-4-8
This commit is contained in:
+3
-2
@@ -67,8 +67,9 @@ RUN adduser -D -H -s /sbin/nologin pixad && \
|
||||
mkdir -p /var/lib/pixa /etc/pixa && \
|
||||
chown pixad:pixad /var/lib/pixa
|
||||
|
||||
# Copy default config (edit signing_key before use)
|
||||
COPY config.example.yml /etc/pixa/config.yml
|
||||
# Copy the image config; signing_key comes from PIXA_SIGNING_KEY.
|
||||
# Mount a file over /etc/pixa/config.yml to override anything else.
|
||||
COPY config.docker.yml /etc/pixa/config.yml
|
||||
|
||||
USER pixad
|
||||
WORKDIR /var/lib/pixa
|
||||
|
||||
Reference in New Issue
Block a user