Externalize auth secrets to .env and rename default config to triggershell.yml
sessionSecret was previously baked directly into the scaffolded config file;
`triggershell init` now generates a .env with TRIGGERSHELL_SESSION_SECRET
instead and references it via ${VAR} interpolation, keeping the actual
secret out of the (often committed) config file. `triggershell dev/start/
validate` load that .env automatically without overriding real env vars.
Also renames the default config filename from triggershell.config.yaml to
triggershell.yml throughout the CLI, app, docs, and examples.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
# Copy this file to `.env` (same directory as triggershell.yml) and set a real value.
|
||||
# TriggerShell loads .env automatically from the config file's directory and makes its
|
||||
# variables available to ${VAR} interpolation in the config - this is how secrets like
|
||||
# sessionSecret should be kept out of the config file (and out of version control).
|
||||
TRIGGERSHELL_SESSION_SECRET=dev-only-insecure-session-secret-change-me-before-deploying
|
||||
Reference in New Issue
Block a user