fix(smtp): inject SMTP password secret via entrypoint, not *_FILE
The official discourse/discourse image has no *_FILE support, so DISCOURSE_SMTP_PASSWORD_FILE was silently ignored and SMTP auth booted without a password. Read the secret in the wrapper entrypoint and export DISCOURSE_SMTP_PASSWORD, mirroring the DB password handling. Bump APP_ENTRYPOINT_VERSION so the new entrypoint config redeploys. Add release notes for the bitnami->official SMTP env var renames. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,5 @@
|
|||||||
export DB_ENTRYPOINT_VERSION=v3
|
export DB_ENTRYPOINT_VERSION=v3
|
||||||
export PG_BACKUP_VERSION=v2
|
export PG_BACKUP_VERSION=v2
|
||||||
export APP_ENTRYPOINT_VERSION=v1
|
export APP_ENTRYPOINT_VERSION=v2
|
||||||
export APP_INSTALL_SSL_VERSION=v1
|
export APP_INSTALL_SSL_VERSION=v1
|
||||||
export APP_MIGRATE_UPLOADS_VERSION=v1
|
export APP_MIGRATE_UPLOADS_VERSION=v1
|
||||||
|
|||||||
@@ -1,11 +1,15 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
# Co-op Cloud wrapper around the official image's /sbin/boot.
|
# Co-op Cloud wrapper around the official image's /sbin/boot.
|
||||||
# discourse/discourse reads DISCOURSE_DB_PASSWORD from the process env (pups/Ruby;
|
# discourse/discourse reads passwords from the process env (pups/Ruby; it has no
|
||||||
# it has no *_FILE support), so inject it from the docker secret before booting.
|
# *_FILE support), so inject them from the docker secrets before booting.
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
if [ -f /run/secrets/db_password ]; then
|
if [ -f /run/secrets/db_password ]; then
|
||||||
export DISCOURSE_DB_PASSWORD="$(cat /run/secrets/db_password)"
|
export DISCOURSE_DB_PASSWORD="$(cat /run/secrets/db_password)"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
if [ -f /run/secrets/smtp_password ]; then
|
||||||
|
export DISCOURSE_SMTP_PASSWORD="$(cat /run/secrets/smtp_password)"
|
||||||
|
fi
|
||||||
|
|
||||||
exec /sbin/boot
|
exec /sbin/boot
|
||||||
|
|||||||
@@ -3,8 +3,8 @@ version: "3.8"
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
environment:
|
# the wrapper entrypoint reads /run/secrets/smtp_password and exports
|
||||||
- DISCOURSE_SMTP_PASSWORD_FILE=/var/run/secrets/smtp_password
|
# DISCOURSE_SMTP_PASSWORD (the official image has no *_FILE support)
|
||||||
secrets:
|
secrets:
|
||||||
- smtp_password
|
- smtp_password
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
This release switches from the bitnami image to the official discourse/discourse
|
||||||
|
image. Some env vars need to be renamed for this migration; everything else
|
||||||
|
should happen automatically.
|
||||||
|
|
||||||
|
Rename these in your app's .env (the values carry over):
|
||||||
|
|
||||||
|
DISCOURSE_SMTP_HOST --> DISCOURSE_SMTP_ADDRESS
|
||||||
|
DISCOURSE_SMTP_USER --> DISCOURSE_SMTP_USER_NAME
|
||||||
|
DISCOURSE_SMTP_AUTH --> DISCOURSE_SMTP_AUTHENTICATION
|
||||||
|
DISCOURSE_SMTP_PROTOCOL --> DISCOURSE_SMTP_ENABLE_START_TLS
|
||||||
|
|
||||||
|
Note: DISCOURSE_SMTP_ENABLE_START_TLS takes a boolean (true/false), not the old
|
||||||
|
tls/ssl value, so translate it rather than copying it straight across.
|
||||||
Reference in New Issue
Block a user