docs: get dev secrets from OpenBao, keep env files as the manual setup #94

Merged
jalenluorion merged 1 commit from docs/openbao-setup into main 2026-10-03 22:49:20 +00:00
Member

The getting-started guide now pulls dev secrets from OpenBao instead of asking the tech lead for env files:

  • bao login -address=https://secrets.scottylabs.org -method=oidc, then secretspec run -P dev -- ... for the API, web app and migrations. Governance already gives /projects/cal members read access to cal/dev.
  • The old env-file steps become "Manual setup", which also points at the OpenBao web UI for the values.
  • web/.env.development (committed, unignored) holds the two public local values, NEXT_PUBLIC_API_URL and APP_URL, which are not in the dev profile. next build does not read it.

Tested from this branch: secretspec check -P dev finds all 21 values, the API comes up and reads the dev database, and /api/auth/login redirects to Keycloak with the cal-dev client.

The getting-started guide now pulls dev secrets from OpenBao instead of asking the tech lead for env files: - `bao login -address=https://secrets.scottylabs.org -method=oidc`, then `secretspec run -P dev -- ...` for the API, web app and migrations. Governance already gives `/projects/cal` members read access to `cal/dev`. - The old env-file steps become "Manual setup", which also points at the OpenBao web UI for the values. - `web/.env.development` (committed, unignored) holds the two public local values, `NEXT_PUBLIC_API_URL` and `APP_URL`, which are not in the dev profile. `next build` does not read it. Tested from this branch: `secretspec check -P dev` finds all 21 values, the API comes up and reads the dev database, and `/api/auth/login` redirects to Keycloak with the cal-dev client.
docs: get dev secrets from OpenBao, keep env files as the manual setup
All checks were successful
kennel/build build succeeded
CI / check-1 (pull_request) Successful in 3m13s
CI / build (pull_request) Successful in 7m17s
CI / check (pull_request) Successful in 0s
85f02770cf
Members of the CMUCal team can read cal/dev in OpenBao, so the guide now runs
the API and web app under secretspec run -P dev instead of handing out env
files. The public web values move to a committed web/.env.development.
jalenluorion deleted branch docs/openbao-setup 2026-10-03 22:49:20 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ScottyLabs/cal!94
No description provided.