README Configuration table leaves out settings upaas reads and misstates some defaults and effects #229

Open
opened 2026-09-29 02:51:17 +02:00 by clawbot · 0 comments
Collaborator

The Configuration table in README.md leaves out three settings upaas reads (UPAAS_MAINTENANCE_MODE, UPAAS_SESSION_SECRET, UPAAS_CORS_ORIGINS), and several rows it has give the wrong default or effect. Found while fixing #224.

Definition of done: every setting upaas reads from the environment is in the table, with its real name, default and effect, checked against internal/config/config.go and the code that uses each value. Docs only.

What the code does today (verify each before writing it down):

  • PORT: upaas also reads UPAAS_PORT, and UPAAS_PORT wins when both are set (the config library looks up the prefixed name first).
  • UPAAS_HOST_DATA_DIR: when unset it takes the value of UPAAS_DATA_DIR; when set it must be an absolute path or upaas refuses to start. It is needed when upaas runs in a container.
  • UPAAS_DEBUG: turns on debug logging and also drops the Secure flag from the session cookie (internal/service/auth/auth.go).
  • UPAAS_SENTRY_DSN: read but not used anywhere; upaas sends nothing to Sentry. The row must say so instead of promising error reporting.
  • UPAAS_METRICS_USERNAME / UPAAS_METRICS_PASSWORD: /metrics is served only when the username is set, behind basic auth with these credentials.
  • UPAAS_MAINTENANCE_MODE (default false): only shown as maintenanceMode in the /health response; it blocks nothing.
  • UPAAS_SESSION_SECRET: signs session cookies and CSRF tokens. When unset, a random secret is generated once and kept in $UPAAS_DATA_DIR/session.key.
  • UPAAS_CORS_ORIGINS: comma-separated origins allowed to make cross-origin requests with cookies. Unset means no CORS headers are sent.
  • The Docker client (internal/docker/client.go) also reads the standard DOCKER_API_VERSION, DOCKER_CERT_PATH and DOCKER_TLS_VERIFY; UPAAS_DOCKER_HOST (which has a default) always overrides DOCKER_HOST. One sentence under the table covers this.

Also: one dated entry at the top of Completed Steps in TODO.md, in the style of the others, ending with this issue's number.

Out of scope: code changes; the YAML config file upaas can also read; the Compose port problem, which is filed separately.

Model: opus-5-5

The Configuration table in `README.md` leaves out three settings upaas reads (`UPAAS_MAINTENANCE_MODE`, `UPAAS_SESSION_SECRET`, `UPAAS_CORS_ORIGINS`), and several rows it has give the wrong default or effect. Found while fixing https://git.eeqj.de/sneak/upaas/issues/224. Definition of done: every setting upaas reads from the environment is in the table, with its real name, default and effect, checked against `internal/config/config.go` and the code that uses each value. Docs only. What the code does today (verify each before writing it down): - `PORT`: upaas also reads `UPAAS_PORT`, and `UPAAS_PORT` wins when both are set (the config library looks up the prefixed name first). - `UPAAS_HOST_DATA_DIR`: when unset it takes the value of `UPAAS_DATA_DIR`; when set it must be an absolute path or upaas refuses to start. It is needed when upaas runs in a container. - `UPAAS_DEBUG`: turns on debug logging and also drops the `Secure` flag from the session cookie (`internal/service/auth/auth.go`). - `UPAAS_SENTRY_DSN`: read but not used anywhere; upaas sends nothing to Sentry. The row must say so instead of promising error reporting. - `UPAAS_METRICS_USERNAME` / `UPAAS_METRICS_PASSWORD`: `/metrics` is served only when the username is set, behind basic auth with these credentials. - `UPAAS_MAINTENANCE_MODE` (default false): only shown as `maintenanceMode` in the `/health` response; it blocks nothing. - `UPAAS_SESSION_SECRET`: signs session cookies and CSRF tokens. When unset, a random secret is generated once and kept in `$UPAAS_DATA_DIR/session.key`. - `UPAAS_CORS_ORIGINS`: comma-separated origins allowed to make cross-origin requests with cookies. Unset means no CORS headers are sent. - The Docker client (`internal/docker/client.go`) also reads the standard `DOCKER_API_VERSION`, `DOCKER_CERT_PATH` and `DOCKER_TLS_VERIFY`; `UPAAS_DOCKER_HOST` (which has a default) always overrides `DOCKER_HOST`. One sentence under the table covers this. Also: one dated entry at the top of Completed Steps in `TODO.md`, in the style of the others, ending with this issue's number. Out of scope: code changes; the YAML config file upaas can also read; the Compose port problem, which is filed separately. Model: opus-5-5
clawbot self-assigned this 2026-09-29 02:51:17 +02:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/upaas#229