Repository navigation
CI and 26 services: pin actions, validate Compose, require your own secrets - #368
Merged
Merged
Conversation
…thub folder Pin checkout and rumdl to commit SHAs, set contents: read, add a concurrency group and a timeout, and stop ignoring .github/** so that workflow and template changes are linted.
Stacks that require your own secrets get a dummy value for each missing variable, so the rest of the file is still checked.
… own secrets These stacks shipped well-known sample passwords and keys in .env, such as admin/changeme. A stack started with them unless the user replaced each one by hand. Leave the secrets empty in .env and make Compose stop with an error when one is missing, as in #367. Document the values and the upgrade steps in each README.
… own database passwords These stacks shipped a well-known database password in .env or as a fallback in compose.yaml. Leave the password empty in .env and make Compose stop with an error when it is missing, as in #367. Tandoor also requires its SECRET_KEY. Document the upgrade steps in each README: an existing database keeps the password it was created with.
These stacks shipped placeholders that start the stack as they are, such as REPLACE_WITH_RANDOM_ALPHANUMERIC_PASSWORD, and Seafile fell back to a known administrator password. Leave the secrets empty in .env and make Compose or the application stop with an error when one is missing, as in #367. Document the upgrade steps in each README.
The stack publishes the web console on all interfaces of the Docker host. Say so in the README and name the line to remove when the console is only used through Tailscale.
A read-only bind mount of docker.sock only protects the socket file. The service can still control Docker, which is root access to the host. Fix the comments and READMEs that suggested otherwise.
SECRET_KEY reached the container only through env_file, so an empty value started the stack. Require it in the application environment, as the README and the previous commit already state.
…lidation loop runs out
…and encryption key A user who kept the sample value and pulls this change ends up with an empty value. The database or the stored data still uses the old one, so say which value to set again.
…enerate each secret
…he sample passwords to .env and require your own
jackspiering
marked this pull request as ready for review
October 9, 2026 11:23
…CRM, Technitium, Seafile: say how to change an existing admin password
crypt0rr
approved these changes
Oct 9, 2026
This was referenced Oct 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Review of the repo against
templates/service-template/andCONTRIBUTING.md(the template placeholder in the request was blank, soAGENTS.mddecided the baseline), plus fixes for the findings that were approved.Review findings
permissions:, concurrency or timeout,.github/**was never linted, and CI did not rundocker compose config.admin/changeme, a Seafile fallback admin passwordasecret, and theREPLACE_WITH_...values that still work as secrets.docker.sockmount does not limit Docker API access. Several comments and READMEs suggested it does.Commits
permissions: contents: read, concurrency, timeout, lint.github/**(planned commits 1 and 2, merged).compose-validation.ymlrunsdocker compose config --quieton every service. Stacks that require their own secrets get a dummy value per missing variable.:rodoes not limit API access (comments and READMEs).SECRET_KEYin the application environment.version: "0.2.78"), so that the linter no longer follows the latest release.SECRET_KEY_BASEin Sure (both containers), and give one way to generate each secret. Tandoor had two commands in.env, and GitSave pointed to a website that generates secrets..env, but Compose started the stack without them. They now have the${VAR:?Set VAR in .env}guard. No sample value was removed, so these stacks have no Upgrading note.compose.yaml(admin,example,postgres,password,<yourkey>) are now empty variables in.envwith the guard, and each README has an Upgrading note that names the old value. Formbricks buildsDATABASE_URLfromPOSTGRES_PASSWORD. FrigateFRIGATE_RTSP_PASSWORDis optional and has no guard, because Frigate only uses it whenconfig.ymlrefers to it..envand the README now ask for letters and digits only.POSTGRES_HOST_AUTH_METHOD: trust, so that the new database password is enforced on a new database (an existing database keeps the setting it was created with). Paperless, EspoCRM, Technitium, Seafile: the Upgrading note says that the admin password variable only applies at the first start and how to change an existing account.The secrets commits follow #367: empty in
.env,${VAR:?Set VAR in .env}incompose.yaml, and an Upgrading note in each README.Related Issues
Verification
docker compose config --quietpasses on all 123 services with dummy values (the CI script, run withbash -eo pipefail). The changed stacks fail without them, by design.rumdl check --config .markdownlint.yml .andgit diff --checkare clean.SETUP_TOKEN must be at least 32 characters).AUTH_SECRETupstream (apps/api/src/utils/auth-secret.ts), so the guard only moves the error to Compose.docker compose configwith its message when the value is empty.docker compose configshows the password from.envin bothPOSTGRES_PASSWORDandDATABASE_URL.Not done
WEBUI_SECRET_KEYand Pocket IDENCRYPTION_KEYhave no guard. Open WebUI generates and stores its own key when the value is empty (backend/start.sh), and Pocket ID also acceptsENCRYPTION_KEY_FILE.TAILNET_NAME(Arcane, FreshRSS, Homepage, Miniflux) andTS_TAILNET(Tracktor) are empty and have no guard. They are not secrets..envkeys and image tags in.env: not evaluated.compose configonly.git pulland keep their old.envare unaffected. Users who recreate.envfrom the template must set the values, and for databases must reuse the old password.Checklist
Additional Context
0.2.78through theversioninput. Update both together.contents: readis enough). The local check ran rumdl 0.2.77; the first CI run shows the installed version.compose-validationbecomes a required check, itspaths:filter leaves PRs that do not touch services waiting. I did not change any repo settings.INIT_*, Paperless admin, FreshRSSADMIN_PASSWORDandADMIN_API_PASSWORD, MinifluxADMIN_PASSWORD, GotifyGOTIFY_DEFAULTUSER_PASS) must stay in.env, as in Arcane, ConvertX, Formbricks, Hemmelig, Karakeep: require your own secrets #367.The pinned SHAs are
actions/checkoutv7.0.13d3c42e5aac5ba805825da76410c181273ba90b1andrvben/rumdlv0.2.789c4cc2a2ebe176de68e1788106e25af8a9bd3899(dereferenced from the annotated tag), the latest release.