|
Some checks failed
PR build (required check) / changes (pull_request) Successful in 26s
secrets-guard / encrypted (pull_request) Successful in 10s
shell-lint / shellcheck (pull_request) Failing after 14s
PR build (required check) / validate-observability (pull_request) Successful in 1m5s
PR build (required check) / build-frontend (pull_request) Successful in 3m47s
PR build (required check) / build-backend (pull_request) Successful in 4m44s
PR build (required check) / gate (pull_request) Successful in 6s
Docker on the LAN box is the snap package, sandboxed to $HOME (plus a short allowlist) -- it can't see /etc/thermograph.env at all, so env_file: /etc/thermograph.env silently loads nothing for every container there, no matter how correctly the vault renders. Confirmed directly: `docker run --env-file /etc/thermograph.env` fails with "no such file or directory" on a file the shell reads fine; the same file under $HOME loads correctly. render-secrets.sh gains an opt-in second write (THERMOGRAPH_SECRETS_ENV_FILE_MIRROR), deploy-dev.sh points it at infra/deploy/dev-secrets.env (gitignored, re-rendered every deploy), and docker-compose.dev.yml adds it as a second env_file entry for backend/daemon/lake -- compose appends env_file lists across overlays, so this is additive and prod/beta (which never set the mirror var) are unaffected. |
||
|---|---|---|
| .. | ||
| backup | ||
| db | ||
| forgejo | ||
| migrations | ||
| openmeteo | ||
| secrets | ||
| stack | ||
| swarm | ||
| twa | ||
| Caddyfile | ||
| deploy-dev.sh | ||
| deploy.sh | ||
| migrate-db.py | ||
| POSTGRES-MIGRATION.md | ||
| provision-agent-access.sh | ||
| provision-dev-lan.sh | ||
| provision-mail-supervision.sh | ||
| provision-mail.sh | ||
| provision-secrets.sh | ||
| render-secrets.sh | ||
| thermograph-dev.service | ||
| thermograph.env.example | ||
| thermograph.service | ||