Settings given as files: the _FILE form of every setting (closes #87)
check / check (push) Successful in 3m29s
check / check (push) Successful in 3m29s
Every setting X may instead be given as a file that X_FILE names, read once at start: its contents, less one trailing newline, are the value, checked as X would be. X and X_FILE both set, or a file that cannot be read, stops the start with a message naming the variable. The logged settings name the file, and mask a token read from one. SWWAF_LOG_REMOTE_TLS_CA_FILE, whose value is a file already, has no _FILE form. The health check reads only SWWAF_LISTEN_ADDR and SWWAF_UPSTREAM_URL, so no other setting or file can fail it. Judgement call: an invalid value read from a file is named as X, not X_FILE. Rule suppressed: gosec G304 on reading the named file, as for the CA file. Model: opus-5-5
This commit is contained in:
@@ -32,7 +32,7 @@ from a directory of hand-editable text files.
|
||||
- Defence against traffic floods that saturate the host's network link. That
|
||||
needs help upstream of the host.
|
||||
- A web UI or a configuration file. Settings are environment variables. Apart
|
||||
from settings given as files (the `_FILE` form of any setting, such as
|
||||
from settings given as files (the `_FILE` form of a setting, such as
|
||||
`SWWAF_ADMIN_TOKEN_FILE`, and `SWWAF_LOG_REMOTE_TLS_CA_FILE`), its own state
|
||||
files and the lookup database, the only files read are the rule files, which
|
||||
hold one regex per line and nothing more elaborate.
|
||||
@@ -298,7 +298,8 @@ it.
|
||||
- A list set to an empty value is an empty list, and replaces the default.
|
||||
- Every setting may instead be given as a file holding the value, named by the
|
||||
setting's name with `_FILE` added, such as `SWWAF_ADMIN_TOKEN_FILE`, for
|
||||
secrets and long lists.
|
||||
secrets and long lists. `SWWAF_LOG_REMOTE_TLS_CA_FILE`, whose value names a
|
||||
file already, has no `_FILE` form.
|
||||
- Settings, including those given as files, are read once at start; changing one
|
||||
means restarting the container. The files `smallwebwaf` watches while it runs
|
||||
are its state files, its rule files and the lookup database.
|
||||
|
||||
Reference in New Issue
Block a user