sessionSecret was previously baked directly into the scaffolded config file;
`triggershell init` now generates a .env with TRIGGERSHELL_SESSION_SECRET
instead and references it via ${VAR} interpolation, keeping the actual
secret out of the (often committed) config file. `triggershell dev/start/
validate` load that .env automatically without overriding real env vars.
Also renames the default config filename from triggershell.config.yaml to
triggershell.yml throughout the CLI, app, docs, and examples.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
6 lines
432 B
Bash
6 lines
432 B
Bash
# Copy this file to `.env` (same directory as triggershell.yml) and set a real value.
|
|
# TriggerShell loads .env automatically from the config file's directory and makes its
|
|
# variables available to ${VAR} interpolation in the config - this is how secrets like
|
|
# sessionSecret should be kept out of the config file (and out of version control).
|
|
TRIGGERSHELL_SESSION_SECRET=dev-only-insecure-session-secret-change-me-before-deploying
|