Commit 1d3ffb8
committed
test: drop plain-text secrets from fixtures, use <attr>File indirection
- services/keycloak/checks.nix: openid_clients.acme_app.client_secret
"topsecret" -> client_secretFile = /etc/acme-app-client-secret.
Asserts the literal stays out of the generated .tf.json.
- services/forgejo/checks.nix: users.alice.password "hackme" in the
widenScope specialisation -> passwordFile = /etc/forgejo-alice-password.
(bob already used passwordFile; alice was the one literal left.)
The fixtures now exclusively exercise the secret-file indirection, so
the tests stay honest examples for operators.1 parent a72e59b commit 1d3ffb8
2 files changed
Lines changed: 13 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
28 | | - | |
| 27 | + | |
| 28 | + | |
29 | 29 | | |
| 30 | + | |
30 | 31 | | |
31 | 32 | | |
32 | 33 | | |
| |||
98 | 99 | | |
99 | 100 | | |
100 | 101 | | |
101 | | - | |
| 102 | + | |
102 | 103 | | |
103 | 104 | | |
104 | 105 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
247 | 247 | | |
248 | 248 | | |
249 | 249 | | |
| 250 | + | |
250 | 251 | | |
251 | 252 | | |
252 | 253 | | |
| |||
264 | 265 | | |
265 | 266 | | |
266 | 267 | | |
267 | | - | |
| 268 | + | |
268 | 269 | | |
269 | 270 | | |
270 | 271 | | |
| |||
320 | 321 | | |
321 | 322 | | |
322 | 323 | | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
323 | 331 | | |
324 | 332 | | |
325 | 333 | | |
| |||
0 commit comments