check / check (push) Failing after 1s
The Docker image now ships config.docker.yml, which sets only signing_key (read from the PIXA_SIGNING_KEY environment variable), state_dir and port. The placeholder key and the five-host allowlist from config.example.yml are no longer in the image; anything else is configured by mounting a file over /etc/pixa/config.yml. A container started without PIXA_SIGNING_KEY exits naming it. Startup now refuses the exact placeholder signing_key from config.example.yml. It is 45 characters long and used to pass the length check, so a deployment could sign URLs with a key that is public in this repository. README Getting Started is corrected to match. What a reader would trip over: the unset-variable error comes from config interpolation, not from validate(); the signing key checks moved into validateSigningKey to stay under the complexity limit. Disclosure: TODO.md is not updated by this change. Model: opus-4-8 (implementation, review); fable-5-1 (landing message)
12 lines
411 B
YAML
12 lines
411 B
YAML
# Pixa configuration baked into the Docker image.
|
|
#
|
|
# The signing key is read from the PIXA_SIGNING_KEY environment
|
|
# variable; startup aborts naming it when it is unset. Every other key
|
|
# is omitted so its default applies. Operators who need more (an
|
|
# allowlist, metrics, and so on) mount their own file over
|
|
# /etc/pixa/config.yml.
|
|
|
|
signing_key: "${ENV:PIXA_SIGNING_KEY}"
|
|
state_dir: /var/lib/pixa
|
|
port: 8080
|