Support loading env vars from secret files #1994
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes #1868
This PR updates how environment variables are read, so that, if the actual env var is not found, it tries to read the equivalent env var but with the
_FILE
suffix.This way, if for example,
DB_PASSWORD
is not set, butDB_PASSWORD_FILE
is, we treat the value as a file path, read it, and return its contents as theDB_PASSWORD
value.Regular env vars will always take precedence, so if both
DB_PASSWORD
andDB_PASSWORD_FILE
are set, the latter will be ignored.