Support developer-specific env vars in sandbox provisioning

Source a gitignored .sandbox.env file (if present) before running
probod-bootstrap so each developer can inject their own secrets
(SSO, API keys, etc.) without committing them to the repo.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2026-03-19 19:21:41 +01:00
parent fc2c3eab61
commit baf8cf0837
3 changed files with 21 additions and 0 deletions

1
.gitignore vendored
View File

@@ -13,6 +13,7 @@ sbom-docker.json
*.crt
*.key
compose/keycloak/probo-realm.json
.sandbox.env
# Generated files (codegen)
__generated__/

View File

@@ -56,6 +56,19 @@ During provisioning, the sandbox automatically generates:
Probod config is at `/etc/probod/config.yml`.
### Custom environment variables
To inject developer-specific secrets (SSO, API keys, etc.) into the sandbox, create a `.sandbox.env` file at the repo root:
```bash
# .sandbox.env (gitignored — never committed)
AUTH_SAML_IDP_METADATA_URL=https://login.example.com/metadata
AUTH_OIDC_CLIENT_ID=my-client-id
AUTH_OIDC_CLIENT_SECRET=s3cret
```
This file is sourced during provisioning before `probod-bootstrap` runs. Any variable set here overrides the defaults. The sandbox must be recreated (`delete` + `create`) for changes to take effect.
## Systemd services
The sandbox provisions three systemd services:

View File

@@ -100,6 +100,13 @@ su - "${LIMA_USER}" -c "export PATH=/usr/local/go/bin:\$HOME/go/bin:\$PATH && cd
mkdir -p /etc/probod
# Load developer-specific overrides (not committed to repo).
if [ -f /workspace/.sandbox.env ]; then
set -a
. /workspace/.sandbox.env
set +a
fi
PROBOD_BASE_URL="http://${VM_IP}:8080" \
AUTH_COOKIE_DOMAIN="${VM_IP}" \
AUTH_COOKIE_SECURE=false \