The runtime stage now copies config.docker.yml, which sets only signing_key (from PIXA_SIGNING_KEY), state_dir, and port. This drops the public placeholder key and the baked-in allowlist from the image, matching how upaas configures apps: environment variables and mounts, no injected config file. Model: opus-4-8
12 lines
411 B
YAML
12 lines
411 B
YAML
# Pixa configuration baked into the Docker image.
|
|
#
|
|
# The signing key is read from the PIXA_SIGNING_KEY environment
|
|
# variable; startup aborts naming it when it is unset. Every other key
|
|
# is omitted so its default applies. Operators who need more (an
|
|
# allowlist, metrics, and so on) mount their own file over
|
|
# /etc/pixa/config.yml.
|
|
|
|
signing_key: "${ENV:PIXA_SIGNING_KEY}"
|
|
state_dir: /var/lib/pixa
|
|
port: 8080
|