Externalize auth secrets to .env and rename default config to triggershell.yml
sessionSecret was previously baked directly into the scaffolded config file;
`triggershell init` now generates a .env with TRIGGERSHELL_SESSION_SECRET
instead and references it via ${VAR} interpolation, keeping the actual
secret out of the (often committed) config file. `triggershell dev/start/
validate` load that .env automatically without overriding real env vars.
Also renames the default config filename from triggershell.config.yaml to
triggershell.yml throughout the CLI, app, docs, and examples.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+6
-1
@@ -13,8 +13,13 @@ venv/
|
||||
# Runtime data (created by `triggershell start/dev` in whatever directory the config lives in)
|
||||
.triggershell/
|
||||
|
||||
# Secrets loaded by `triggershell` via ${VAR} interpolation - never commit these
|
||||
.env
|
||||
.env.*
|
||||
!.env.example
|
||||
|
||||
# Local config files a developer might create while testing against this repo
|
||||
/triggershell.config.yaml
|
||||
/triggershell.yml
|
||||
|
||||
# Editors / OS
|
||||
.DS_Store
|
||||
|
||||
Reference in New Issue
Block a user