Container Environment
Configure the image of the platform’s official container using the PROBOD_* environment variables, required secrets, AWS secret references, and boot behavior.
The official container image uses probod-bootstrap to convert the environment variables PROBOD_* into a YAML configuration file before starting probod.
Startup behavior
Posts Tagged ‘startup behavior’CONFIG_FILE selects the generated or mounted configuration file and fails at /etc/probod/config.yml.
Each container starts with:
- When
PROBOD_ENCRYPTION_KEYis set, the input point generatesCONFIG_FILEfrom the environment. - Otherwise, the input point uses the existing
CONFIG_FILE. - Startups fail when none of the sources are available.
This causes PROBOD_ENCRYPTION_KEY to switch between the environment-generated and the directly managed configuration.
Required inputs
Section entitled “Required Inputs”probod-bootstrap requires four persistent secrets:
| Variable | Purpose |
|---|---|
PROBOD_ENCRYPTION_KEY |
Encrypts sensitive application data at rest |
PROBOD_AUTH_COOKIE_SECRET |
Signs session cookies |
PROBOD_AUTH_PASSWORD_PEPPER |
Adds a deployment secret to password hashing |
PROBOD_OAUTH2_SERVER_SIGNING_KEY |
RSA private key used to sign OAuth 2.0 tokens |
Generate separate random values for the first three settings and an RSA key for the signature key:
openssl rand -base64 32openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048Set these values before the start of the first production, keep them stable during restarts and enforcement trials, and include them in recovery procedures.
Configure the application
Section entitled “Configure the application”Set infrastructure and application values alongside the required secrets This minimum example shows the main entries; it is not a complete list of variables.
PROBOD_BASE_URL=https://probo.example.comPROBOD_API_ADDR=0.0.0.0:8080PROBOD_API_CORS_ALLOWED_ORIGINS=https://probo.example.com
PROBOD_PG_ADDR=postgres.example.com:5432PROBOD_PG_USERNAME=probodPROBOD_PG_PASSWORD=replace-mePROBOD_PG_DATABASE=probod
PROBOD_AWS_REGION=eu-west-1PROBOD_AWS_BUCKET=probo-productionThe bootstrap process applies documented default settings, converts strings to the required types, and fails before the file is written when a required value is missing or a value cannot be analyzed.
Special input behavior
Section entitled “Special input behavior”PROBOD_PG_CA_BUNDLE_PATHreads a PostgreSQL CA package from a file and has priority over the inlinePROBOD_PG_CA_BUNDLE.- When both
PROBOD_SAML_CERTIFICATEandPROBOD_SAML_PRIVATE_KEYare absent, bootstrap generates a pair. - Setting up a connector client ID activates that connector and requires client secret. Slack also requires signature secret; Vercel also requires the integration servant.
- Separate coma entries are cut and converted into lists.
- Boolean values use
trueorfalse. complete reference. - PEM values must preserve their line breaks.
External secret references
Section “External secret references”Each value read by probod-bootstrap can be a literal reference or a secret referenceAWS:
| Syntax | Service |
|---|---|
awssm://<secret-id> |
AWS Secrets Manager |
aws://<secret-id> |
AWS Secrets Manager alias |
awsps://<parameter-name> |
AWS Systems Manager Parameter Store |
PROBOD_ENCRYPTION_KEY=awssm://probo/production/encryption-keyPROBOD_AUTH_COOKIE_SECRET=awsps:///probo/production/cookie-secretThe secret resolution uses the standard AWSSDK credential and region chain. PROBOD_AWS_* configures the storage of platform objects; it does not authenticate the secret resolution.
Apply changes
Section entitled “Apply changes”The generated file is a boot artefact, and probod does not reload it.