Skip to content

check values are set for cloud.gov secrets #5804

Description

@FuhuXia

We configure several secret values as a user-provided service for each app, but not all are documented. In some cases, the app may continue to function even when required values are missing, introducing a potential security risk. The app should validate that all required values are set and fail with a clear error if any are missing.

This comes out of a slack discussion.

Activity

  1. SueValente commented on Apr 3, 2026

    @SueValente
    Contributor

    Documentation Epic

  2. moved this from Next Up to 📟 Sprint Backlog in data.gov team boardon Apr 23, 2026
  3. moved this from 📟 Sprint Backlog to No status in data.gov team boardon Apr 30, 2026
  4. added
    Security - complianceRelating to security compliance or documentation
    O&MOperations and maintenance tasks for the Data.gov platform
    on Jun 24, 2026
  5. modified the milestones: 2026 07, 2026 08 on Jun 24, 2026
  6. moved this from O&M Specific Backlog to 📟 Sprint Backlog (Top Priority) in data.gov team boardon Aug 12, 2026
  7. self-assigned this
    on Aug 27, 2026
  8. moved this from 📟 Sprint Backlog (Top Priority) to 🏗 In Progress in data.gov team boardon Aug 27, 2026
  9. FuhuXia commented on Sep 1, 2026

    @FuhuXia
    MemberAuthor

    repos checked:

    • datagov-harvest
    • datagov-catalog
    • inventory-app

    Security-related secrets are checked at application startup. Some functionality-specific secrets are not checked at startup; if they are missing, only the corresponding functionality will fail—for example, OPENID_PRIVATE_KEY or CF_SERVICE_AUTH. Not validating these secrets at startup does not introduce a security risk. Missing those functionality-specific secrets should not stop the app from starting.

    Closing this ticket.

    [UPDATE]
    There is a bad-name secret API_TOKEN in inventory app that should have been named CKANEXT__XLOADER__API_TOKEN. Add ing it to the inventory startup check.

  10. moved this from 🏗 In Progress to ✔ Done in data.gov team boardon Sep 1, 2026
  11. moved this from ✔ Done to 🗄 Closed in data.gov team boardon Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

O&MOperations and maintenance tasks for the Data.gov platformSecurity - complianceRelating to security compliance or documentationbugSoftware defect or bug

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions