diff --git a/.gitignore b/.gitignore index 1ce21b760..caf27bc6d 100644 --- a/.gitignore +++ b/.gitignore @@ -13,6 +13,7 @@ sbom-docker.json *.crt *.key compose/keycloak/probo-realm.json +.sandbox.env # Generated files (codegen) __generated__/ diff --git a/contrib/claude/sandbox.md b/contrib/claude/sandbox.md index d51715aab..879c26950 100644 --- a/contrib/claude/sandbox.md +++ b/contrib/claude/sandbox.md @@ -56,6 +56,19 @@ During provisioning, the sandbox automatically generates: Probod config is at `/etc/probod/config.yml`. +### Custom environment variables + +To inject developer-specific secrets (SSO, API keys, etc.) into the sandbox, create a `.sandbox.env` file at the repo root: + +```bash +# .sandbox.env (gitignored — never committed) +AUTH_SAML_IDP_METADATA_URL=https://login.example.com/metadata +AUTH_OIDC_CLIENT_ID=my-client-id +AUTH_OIDC_CLIENT_SECRET=s3cret +``` + +This file is sourced during provisioning before `probod-bootstrap` runs. Any variable set here overrides the defaults. The sandbox must be recreated (`delete` + `create`) for changes to take effect. + ## Systemd services The sandbox provisions three systemd services: diff --git a/contrib/lima/provision.sh b/contrib/lima/provision.sh index 202aa558e..f738b0c38 100755 --- a/contrib/lima/provision.sh +++ b/contrib/lima/provision.sh @@ -100,6 +100,13 @@ su - "${LIMA_USER}" -c "export PATH=/usr/local/go/bin:\$HOME/go/bin:\$PATH && cd mkdir -p /etc/probod +# Load developer-specific overrides (not committed to repo). +if [ -f /workspace/.sandbox.env ]; then + set -a + . /workspace/.sandbox.env + set +a +fi + PROBOD_BASE_URL="http://${VM_IP}:8080" \ AUTH_COOKIE_DOMAIN="${VM_IP}" \ AUTH_COOKIE_SECURE=false \