Security: remove hardcoded credentials, fix db_init for non-owner users #1
Reference in New Issue
Block a user
Delete Branch "security/remove-hardcoded-secrets"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
config.yamlund.env(die.envwar im Git eingecheckt)env_file: .envin derdocker-compose.yaml.env.exampleals Vorlage hinzu;.envist per.gitignoreausgeschlossenMIGRATION.mdmit vollständigem Runbook für Secret-Rotation und Server-Umzugdb_initfür DB-User ohne Table-Ownership:ALTER TABLE,CREATE INDEXundCREATE FUNCTIONwerden nur ausgeführt wenn das Objekt noch nicht existiertTest plan
.envaus.env.exampleerstellen und mit rotierten Credentials befüllendocker compose up -d --builderfolgreich[RESULT] ... result=successicu/processed/undicu/thumbnails/SELECT status, count(*) FROM remote_cam.import_job GROUP BY 1;zeigt verarbeitete Jobs