Repository navigation
check values are set for cloud.gov secrets #5804
Copy link
Copy link
Closed
Labels
O&MOperations and maintenance tasks for the Data.gov platformOperations and maintenance tasks for the Data.gov platformSecurity - complianceRelating to security compliance or documentationRelating to security compliance or documentationbugSoftware defect or bugSoftware defect or bug
Milestone
Description
Activity
Documentation Epic
- added a parent issue
on May 14, 2026 - addedSecurity - complianceRelating to security compliance or documentationRelating to security compliance or documentationO&MOperations and maintenance tasks for the Data.gov platformOperations and maintenance tasks for the Data.gov platform
on Jun 24, 2026 - removed a parent issue
on Jul 7, 2026 - moved this from O&M Specific Backlog to 📟 Sprint Backlog (Top Priority) in data.gov team board
on Aug 12, 2026 - moved this from 📟 Sprint Backlog (Top Priority) to 🏗 In Progress in data.gov team board
on Aug 27, 2026 repos checked:
- datagov-harvest
- datagov-catalog
- inventory-app
Security-related secrets are checked at application startup. Some functionality-specific secrets are not checked at startup; if they are missing, only the corresponding functionality will fail—for example, OPENID_PRIVATE_KEY or CF_SERVICE_AUTH. Not validating these secrets at startup does not introduce a security risk. Missing those functionality-specific secrets should not stop the app from starting.
Closing this ticket.
[UPDATE]
There is a bad-name secretAPI_TOKENin inventory app that should have been namedCKANEXT__XLOADER__API_TOKEN. Add ing it to the inventory startup check.- moved this from 🏗 In Progress to ✔ Done in data.gov team board
on Sep 1, 2026
Metadata
Metadata
Assignees
Labels
O&MOperations and maintenance tasks for the Data.gov platformOperations and maintenance tasks for the Data.gov platformSecurity - complianceRelating to security compliance or documentationRelating to security compliance or documentationbugSoftware defect or bugSoftware defect or bug
Type
Projects
- StatusShow more project fields🗄 Closed
We configure several secret values as a user-provided service for each app, but not all are documented. In some cases, the app may continue to function even when required values are missing, introducing a potential security risk. The app should validate that all required values are set and fail with a clear error if any are missing.
This comes out of a slack discussion.