Add a mutex around loading secrets
Loading secrets may ask for use input, so we need to ensure only one thread does it at a time.
This commit is contained in:
@@ -9,7 +9,7 @@ class Kamal::Configuration
|
|||||||
delegate :service, :image, :labels, :stop_wait_time, :hooks_path, to: :raw_config, allow_nil: true
|
delegate :service, :image, :labels, :stop_wait_time, :hooks_path, to: :raw_config, allow_nil: true
|
||||||
delegate :argumentize, :optionize, to: Kamal::Utils
|
delegate :argumentize, :optionize, to: Kamal::Utils
|
||||||
|
|
||||||
attr_reader :destination, :raw_config
|
attr_reader :destination, :raw_config, :secrets
|
||||||
attr_reader :accessories, :aliases, :boot, :builder, :env, :healthcheck, :logging, :traefik, :servers, :ssh, :sshkit, :registry
|
attr_reader :accessories, :aliases, :boot, :builder, :env, :healthcheck, :logging, :traefik, :servers, :ssh, :sshkit, :registry
|
||||||
|
|
||||||
include Validation
|
include Validation
|
||||||
@@ -64,6 +64,8 @@ class Kamal::Configuration
|
|||||||
@ssh = Ssh.new(config: self)
|
@ssh = Ssh.new(config: self)
|
||||||
@sshkit = Sshkit.new(config: self)
|
@sshkit = Sshkit.new(config: self)
|
||||||
|
|
||||||
|
@secrets = Kamal::Secrets.new(destination: destination)
|
||||||
|
|
||||||
ensure_destination_if_required
|
ensure_destination_if_required
|
||||||
ensure_required_keys_present
|
ensure_required_keys_present
|
||||||
ensure_valid_kamal_version
|
ensure_valid_kamal_version
|
||||||
|
|||||||
@@ -8,10 +8,14 @@ class Kamal::Secrets
|
|||||||
def initialize(destination: nil)
|
def initialize(destination: nil)
|
||||||
@secrets_files = \
|
@secrets_files = \
|
||||||
[ ".kamal/secrets-common", ".kamal/secrets#{(".#{destination}" if destination)}" ].select { |f| File.exist?(f) }
|
[ ".kamal/secrets-common", ".kamal/secrets#{(".#{destination}" if destination)}" ].select { |f| File.exist?(f) }
|
||||||
|
@mutex = Mutex.new
|
||||||
end
|
end
|
||||||
|
|
||||||
def [](key)
|
def [](key)
|
||||||
secrets.fetch(key)
|
# Fetching secrets may ask the user for input, so ensure only one thread does that
|
||||||
|
@mutex.synchronize do
|
||||||
|
secrets.fetch(key)
|
||||||
|
end
|
||||||
rescue KeyError
|
rescue KeyError
|
||||||
if secrets_files
|
if secrets_files
|
||||||
raise Kamal::ConfigurationError, "Secret '#{key}' not found in #{secrets_files.join(", ")}"
|
raise Kamal::ConfigurationError, "Secret '#{key}' not found in #{secrets_files.join(", ")}"
|
||||||
|
|||||||
Reference in New Issue
Block a user