Many apps read their configuration from files rather than from environment variables. Today the closest thing (I could think of at least :-)) phase offers is:
phase run --env production -- envsubst < config.tpl > config.txt
This works, but envsubst has two issues in this context:
- Unknown variables silently become empty strings. If a key is missing in Phase, a config with i.e.
db.password= ends up on the server, and nothing reports an error.
- It substitutes every $VAR from the process environment ($HOME, $PATH, …), not just Phase secrets. You have to pass an explicit variable list to prevent that.
So I wonder if something like envsubst, but fed directly from Phase with some checking might be useful for others as well:
phase subst --app my-app --env production < config.tpl > config.txt
phase subst --env production -i web.tpl.xml -o web.xml
db.host = ${DB_HOST}
db.pass = ${DB_PASSWORD}
- Replaces
${KEY} only with secrets from phase, ignores other env-variables
- Fails with a non-zero exit code if a referenced key doesn't exist
- Nice to have: support the existing reference syntax (
${staging.KEY})
My main inspiration: op inject from 1Password
Many apps read their configuration from files rather than from environment variables. Today the closest thing (I could think of at least :-)) phase offers is:
phase run --env production -- envsubst < config.tpl > config.txt
This works, but envsubst has two issues in this context:
db.password=ends up on the server, and nothing reports an error.So I wonder if something like
envsubst, but fed directly from Phase with some checking might be useful for others as well:${KEY}only with secrets from phase, ignores other env-variables${staging.KEY})My main inspiration: op inject from 1Password