move db passwords into secrets/

This commit is contained in:
2025-05-20 08:12:55 -07:00
parent 1e6271e2fd
commit 676013d6d7
2 changed files with 8 additions and 4 deletions

1
.gitignore vendored
View File

@@ -1,2 +1,3 @@
*~ *~
env env
secrets

View File

@@ -26,10 +26,13 @@ services:
image: mariadb image: mariadb
container_name: brewblogger-mariadb container_name: brewblogger-mariadb
restart: unless-stopped restart: unless-stopped
# environment: environment:
# - MARIADB_ROOT_PASSWORD=super-secret-password MARIADB_USER: brewblogger
# # set MARIADB_ROOT_PASSWORD for first run only MARIADB_DATABASE: brewblogger
MARIADB_ROOT_PASSWORD_FILE: /run/secrets/MARIADB_ROOT_PASSWORD
MARIADB_PASSWORD_FILE: /run/secrets/BREWBLOGGER_DB_PASSWORD
volumes: volumes:
- ./secrets:/run/secrets
- brewblogger-db:/var/lib/mysql - brewblogger-db:/var/lib/mysql
networks: networks:
- brewblogger - brewblogger
@@ -40,7 +43,7 @@ services:
network_mode: none network_mode: none
command: [ "tail", "-f", "/dev/null" ] command: [ "tail", "-f", "/dev/null" ]
labels: labels:
caddy: beerandloafing.org caddy: www.beerandloafing.org
caddy.redir: https://beerandloafing.org{uri} caddy.redir: https://beerandloafing.org{uri}
networks: networks: