Files
atomic-design-poc/backend/openzaak/render-prod-secrets.sh
T
ehoandClaude Sonnet 5 8560746d15 refactor: strip WP-/RB- ticket refs from backend (RD-19)
The backend half of the sweep RD-18 did for the front end. git blame
holds the provenance and stays correct when the code moves; the
comment names a closed ticket and tells the reader nothing the
sentence around it does not.

public/letter.css and LetterHtml.golden.html change together, because
the renderer inlines the CSS and the golden file snapshots the
result.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:48:08 +02:00

17 lines
926 B
Bash
Executable File

#!/usr/bin/env bash
# Renders setup_configuration/data.prod.yaml.template into the gitignored
# data.prod.yaml docker-compose.openzaak.prod.yml mounts over the container's data.yaml.
# Run this once before `docker compose ... up` in a production deploy; re-run whenever the
# secrets rotate. Fails fast (no output file) if a required env var is missing — never
# silently falls back to a real-looking default.
set -euo pipefail
cd "$(dirname "${BASH_SOURCE[0]}")"
: "${OPENZAAK_SITE_DOMAIN:?OPENZAAK_SITE_DOMAIN must be set (e.g. open-zaak.example.org)}"
: "${OPENZAAK_CLIENT_ID:?OPENZAAK_CLIENT_ID must be set}"
: "${OPENZAAK_CLIENT_SECRET:?OPENZAAK_CLIENT_SECRET must be set}"
: "${OPENZAAK_APPLICATIE_UUID:?OPENZAAK_APPLICATIE_UUID must be set (a fresh UUID, e.g. \$(uuidgen))}"
envsubst < setup_configuration/data.prod.yaml.template > setup_configuration/data.prod.yaml
echo "Wrote setup_configuration/data.prod.yaml"