feat(config): support Docker secrets via API_KEY_FILE - #74
Merged
Conversation
API_KEY_FILE points to a file whose content becomes the API key(s), following the _FILE convention of official Docker images — e.g. API_KEY_FILE=/run/secrets/immich_api_key with a Swarm or compose secret. The content is trimmed (secret files usually end with a newline) and supports the same comma-separated multi-key format as API_KEY. Setting both API_KEY and API_KEY_FILE is an error so there is never an ambiguity about which key is in use. The docs already recommended Docker secrets as a best practice without the tool being able to consume them; the integration pages now show how. Closes #73
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #73
What
API_KEY_FILEpoints to a file whose content becomes the API key(s), following the_FILEconvention of official Docker images:Behavior
API_KEYis supported, so multi-user setups work unchanged.API_KEY(or--api-key) andAPI_KEY_FILEare mutually exclusive: setting both is a startup error, so there is never an ambiguity about which key is in use. A missing or unreadable file is also a clear startup error.Docs
The integration docs recommended Docker secrets as a best practice without the tool being able to consume them. The environment-variables reference now documents
API_KEY_FILE, the Docker page links the recommendation to it, and the compose page gains a working secrets example.Testing
Table-driven tests cover: plain file, trailing newline, comma-separated keys, missing file, both variables set, and empty file.
go test -race ./...green.