From 09d33a4273ffa26c16f3949514b98dad78344dbf Mon Sep 17 00:00:00 2001 From: argszero Date: Mon, 14 Sep 2026 19:16:54 +0800 Subject: [PATCH] fix(deploy): require ATP_MASTER_KEY in docker-compose instead of defaulting to an invalid value MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Host report (rant 2026-09-14T17:30:56). `docker-compose.yml` set `ATP_MASTER_KEY=${ATP_MASTER_KEY:-dev-master-key-请替换}`. That default is not a 64-hex string (18 chars; contains `-` and CJK characters), so `crypto::parse_master_key` rejects it and `Crypto::from_config` logs an error and **falls through** (src/crypto.rs:41) to the random dev key (src/crypto.rs:56-58). A restart then makes every already-encrypted upstream key undecryptable, i.e. every upstream call returns 503 - a silent full outage that looks like a key problem rather than a configuration one. Fail loud instead of shipping a default: `${ATP_MASTER_KEY:?msg}` makes `docker compose` refuse to start and print the generation command. This is deliberately **not** a valid-hex default - that would trade "breaks on restart" for "every deployment shares one public master key". The header comment claiming "未设置时使用示例默认值" is corrected too: the value it described could never be parsed, so the comment documented behaviour that does not exist. - docker-compose.yml: the environment entry uses `${ATP_MASTER_KEY:?…}`, the quick-start shows the required `export`, and the misleading comment is fixed. This is the only tracked artifact that *sets* a value; Dockerfile, READMEs, README.en.md, docs/architecture.md and config.example.toml all only show `openssl rand -hex 32` examples or describe the env var. Tests: `cargo test` unchanged at 245 passed / 0 failed (this file is deployment glue and is not compiled). `cargo fmt --check` exit 0. Verified locally by parsing the YAML and running an explicit model of compose interpolation (`${VAR:?}` / `${VAR:-def}`): unset -> error, empty -> error, set-valid -> ok; the old default is confirmed non-hex. `docker compose config` is the authoritative check but docker is not installed on this machine, so that step is left to a docker-capable environment / CI. --- docker-compose.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index 032fed5..3494617 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,13 +1,15 @@ # AITokenPool — Docker Compose 一键部署(v0.6.6) # # 快速开始: +# export ATP_MASTER_KEY=$(openssl rand -hex 32) # 必填,见下方说明 # docker compose up -d --build # 浏览器打开 http://localhost:8080/ # # ⚠️ 生产环境必须设置 ATP_MASTER_KEY(32 字节 hex 主密钥): # 生成:openssl rand -hex 32 # 注入:export ATP_MASTER_KEY=$(openssl rand -hex 32) && docker compose up -d -# 未设置时使用示例默认值(dev 模式,重启后已加密的上游 key 不可解密,仅用于本地试用)。 +# 未设置时 compose 直接报错退出(本文件不提供默认值):错误的主密钥会让重启后 +# 已加密的上游 key 全部不可解密(全量 503)。本地试用同样请先执行上面的 export。 # # 统一数据目录(rant 2026-08-19T20:53:23):只挂载一个 /data 卷, # config.toml(首次启动自动从内置示例复制)+ aitokenpool.db + logs/ 全在 ./atp-data/ 下。 @@ -22,7 +24,8 @@ services: - ./atp-data:/data environment: # 主密钥(32 字节 hex;env 优先于 config [server].master_key) - - ATP_MASTER_KEY=${ATP_MASTER_KEY:-dev-master-key-请替换} + # 必填:未设置时 docker compose 报错并给出生成命令 + - ATP_MASTER_KEY=${ATP_MASTER_KEY:?未设置 ATP_MASTER_KEY:请提供 32 字节 hex 主密钥(生成:openssl rand -hex 32,见文件顶部说明)} # 统一数据目录(与 Dockerfile CMD --data-dir /data 一致) - ATP_DATA_DIR=/data healthcheck: