jump to content

Container Environment

Configure the image of the platform’s official container using the PROBOD_* environment variables, required secrets, AWS secret references, and boot behavior.

Show as Markdown

The official container image uses probod-bootstrap to convert the environment variables PROBOD_* into a YAML configuration file before starting probod.

CONFIG_FILE selects the generated or mounted configuration file and fails at /etc/probod/config.yml.

Each container starts with:

  1. When PROBOD_ENCRYPTION_KEY is set, the input point generates CONFIG_FILE from the environment.
  2. Otherwise, the input point uses the existing CONFIG_FILE.
  3. Startups fail when none of the sources are available.

This causes PROBOD_ENCRYPTION_KEY to switch between the environment-generated and the directly managed configuration.

probod-bootstrap requires four persistent secrets:

Variable Purpose
PROBOD_ENCRYPTION_KEY Encrypts sensitive application data at rest
PROBOD_AUTH_COOKIE_SECRET Signs session cookies
PROBOD_AUTH_PASSWORD_PEPPER Adds a deployment secret to password hashing
PROBOD_OAUTH2_SERVER_SIGNING_KEY RSA private key used to sign OAuth 2.0 tokens

Generate separate random values for the first three settings and an RSA key for the signature key:

Terminal window
openssl rand -base64 32
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048

Set these values before the start of the first production, keep them stable during restarts and enforcement trials, and include them in recovery procedures.

Set infrastructure and application values alongside the required secrets This minimum example shows the main entries; it is not a complete list of variables.

Terminal window
PROBOD_BASE_URL=https://probo.example.com
PROBOD_API_ADDR=0.0.0.0:8080
PROBOD_API_CORS_ALLOWED_ORIGINS=https://probo.example.com
PROBOD_PG_ADDR=postgres.example.com:5432
PROBOD_PG_USERNAME=probod
PROBOD_PG_PASSWORD=replace-me
PROBOD_PG_DATABASE=probod
PROBOD_AWS_REGION=eu-west-1
PROBOD_AWS_BUCKET=probo-production

The bootstrap process applies documented default settings, converts strings to the required types, and fails before the file is written when a required value is missing or a value cannot be analyzed.

  • PROBOD_PG_CA_BUNDLE_PATH reads a PostgreSQL CA package from a file and has priority over the inline PROBOD_PG_CA_BUNDLE.
  • When both PROBOD_SAML_CERTIFICATE and PROBOD_SAML_PRIVATE_KEY are absent, bootstrap generates a pair.
  • Setting up a connector client ID activates that connector and requires client secret. Slack also requires signature secret; Vercel also requires the integration servant.
  • Separate coma entries are cut and converted into lists.
  • Boolean values use true or false. complete reference.
  • PEM values must preserve their line breaks.

Each value read by probod-bootstrap can be a literal reference or a secret referenceAWS:

Syntax Service
awssm://<secret-id> AWS Secrets Manager
aws://<secret-id> AWS Secrets Manager alias
awsps://<parameter-name> AWS Systems Manager Parameter Store
Terminal window
PROBOD_ENCRYPTION_KEY=awssm://probo/production/encryption-key
PROBOD_AUTH_COOKIE_SECRET=awsps:///probo/production/cookie-secret

The secret resolution uses the standard AWSSDK credential and region chain. PROBOD_AWS_* configures the storage of platform objects; it does not authenticate the secret resolution.

The generated file is a boot artefact, and probod does not reload it.

Ultima actualizare: