Skip to content

Discussion: would a phase subst – envsubst-style substitution of secrets in files be useful? #321

Description

@micheee

Many apps read their configuration from files rather than from environment variables. Today the closest thing (I could think of at least :-)) phase offers is:

phase run --env production -- envsubst < config.tpl > config.txt

This works, but envsubst has two issues in this context:

  • Unknown variables silently become empty strings. If a key is missing in Phase, a config with i.e. db.password= ends up on the server, and nothing reports an error.
  • It substitutes every $VAR from the process environment ($HOME, $PATH, …), not just Phase secrets. You have to pass an explicit variable list to prevent that.

So I wonder if something like envsubst, but fed directly from Phase with some checking might be useful for others as well:

phase subst --app my-app --env production < config.tpl > config.txt
phase subst --env production -i web.tpl.xml -o web.xml
db.host = ${DB_HOST}
db.pass = ${DB_PASSWORD}
  • Replaces ${KEY} only with secrets from phase, ignores other env-variables
  • Fails with a non-zero exit code if a referenced key doesn't exist
  • Nice to have: support the existing reference syntax (${staging.KEY})

My main inspiration: op inject from 1Password

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions