fix(deploy): require ATP_MASTER_KEY in docker-compose instead of defaulting to an invalid value - #235
Merged
Merged
Conversation
…ulting to an invalid value
Host report (rant 2026-09-14T17:30:56).
`docker-compose.yml` set `ATP_MASTER_KEY=${ATP_MASTER_KEY:-dev-master-key-请替换}`.
That default is not a 64-hex string (18 chars; contains `-` and CJK characters),
so `crypto::parse_master_key` rejects it and `Crypto::from_config` logs an error
and **falls through** (src/crypto.rs:41) to the random dev key (src/crypto.rs:56-58).
A restart then makes every already-encrypted upstream key undecryptable, i.e.
every upstream call returns 503 - a silent full outage that looks like a key
problem rather than a configuration one.
Fail loud instead of shipping a default: `${ATP_MASTER_KEY:?msg}` makes
`docker compose` refuse to start and print the generation command. This is
deliberately **not** a valid-hex default - that would trade "breaks on restart"
for "every deployment shares one public master key".
The header comment claiming "未设置时使用示例默认值" is corrected too: the value it
described could never be parsed, so the comment documented behaviour that does
not exist.
- docker-compose.yml: the environment entry uses `${ATP_MASTER_KEY:?…}`, the
quick-start shows the required `export`, and the misleading comment is fixed.
This is the only tracked artifact that *sets* a value; Dockerfile, READMEs,
README.en.md, docs/architecture.md and config.example.toml all only show
`openssl rand -hex 32` examples or describe the env var.
Tests: `cargo test` unchanged at 245 passed / 0 failed (this file is deployment
glue and is not compiled). `cargo fmt --check` exit 0. Verified locally by
parsing the YAML and running an explicit model of compose interpolation
(`${VAR:?}` / `${VAR:-def}`): unset -> error, empty -> error, set-valid -> ok;
the old default is confirmed non-hex. `docker compose config` is the
authoritative check but docker is not installed on this machine, so that step
is left to a docker-capable environment / CI.
8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docker-compose.ymlshipped an invalid default forATP_MASTER_KEY; make it a required variableinstead.
Host report (rant
2026-09-14T17:30:56).The file set:
- ATP_MASTER_KEY=${ATP_MASTER_KEY:-dev-master-key-请替换}That default is not a 64-hex string (18 chars, containing
-and CJK).crypto::parse_master_keyrejects it, and
Crypto::from_configlogs an error and falls through to the random dev key:So the container starts happily, encrypts upstream keys with a random key, and after the first
restart every already-encrypted upstream key is undecryptable - every upstream call returns 503. The
symptom looks like a provider/key problem, not a configuration one.
Related Issue
No issue exists for this - it was reported directly by the host. Left empty on purpose rather than
fabricating one.
Changes
docker-compose.yml:- ATP_MASTER_KEY=${ATP_MASTER_KEY:?未设置 ATP_MASTER_KEY:…}-compose refuses to start and prints the generation command;
export ATP_MASTER_KEY=$(openssl rand -hex 32);never be parsed, i.e. behaviour that does not exist.
into "every deployment shares one public master key", which is strictly worse.
Change radius = 1 file. Carrier scan (
git grepover tracked files):docker-compose.ymlis theonly artifact that sets a value.
Dockerfile:5,README.md:37,README.en.md:37,docs/architecture.md:88andconfig/config.example.toml:20all only showopenssl rand -hex 32examples or describe the env var. No
dev-master-keyreference remains.app config - no example-file counterpart)
Tests
cargo testunchanged - 245 passed / 0 failed (this file is deployment glue; it is notcompiled and no test reads it)
cargo fmt --checkexit 0New tests added (n/a - no Rust code changed)
Local pre-validation (YAML parse + an explicit model of compose interpolation, not docker
itself):
environmententry present${VAR:?msg}:-default survivesdocker compose configmust fail without the variable andsucceed with it. Docker is not installed on this machine (
docker: command not found), so thishas to run in a docker-capable environment or CI. The local probe is explicitly a model of the
interpolation, not the tool.
Checklist
fix/compose-master-key-requiredDeployment note
Anyone running
docker compose upfrom this file must now setATP_MASTER_KEYfirst(
export ATP_MASTER_KEY=$(openssl rand -hex 32)); without it compose stops with a clear messageinstead of silently starting with a broken key. Existing deployments that already pass the variable
are unaffected.