Repository navigation
fix(clickhouse): support env:VAR / vault: spec syntax for credentials - #57
Merged
Merged
Conversation
added 3 commits
May 27, 2026 12:41
Resolves clickhouse.username and clickhouse.password as credential specs at startup via hyperi_rustlib::credential::resolve. The YAML field accepts env:VAR_NAME (read from environment, hard error if unset), vault:path:key (requires the secrets rustlib feature; off by default, so vault: returns VaultUnsupported), or a literal value. Adds "credential" to the hyperi-rustlib feature list. Updates config.example.yaml to document the new syntax. Closes #56. Depends on hyperi-io/hyperi-rustlib#40.
`main.rs` is a separate binary crate whose `crate::` root has no `config`
module — only the library crate does. The Phase 3 commit's
`crate::config::credentials::...` therefore failed to compile when the
binary was built (the lib-only test runs missed this because they don't
touch main.rs).
Use `dfe_loader::config::credentials::...` instead, matching the existing
`use dfe_loader::config::{Config, ...}` pattern elsewhere in main.rs.
kazmosahebi
force-pushed
the
feat/clickhouse-env-credentials
branch
from
May 27, 2026 02:42
5bc0da9 to
f68eea4
Compare
env:VAR / vault: spec syntax for credentialsenv:VAR / vault: spec syntax for credentials
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
src/config/credentials.rs:resolve_clickhouse_credentials(&mut ClickHouseConfig)resolvesenv:VAR/vault:path:key/ literal specs onusernameandpasswordviahyperi_rustlib::credential::resolve.run_service'sasync moveblock — runs once at startup, before theFrom<&loader::ClickHouseConfig>bridge to the internal client config."credential"to the existinghyperi-rustlibfeature list (does not add"secrets"— vault paths returnVaultUnsupported).config.example.yamlwith inline comments documenting the spec syntax and anenv:CLICKHOUSE_USERNAME/env:CLICKHOUSE_PASSWORDexample block.Closes #56.
Why
Today, if a deployment sets
CLICKHOUSE_PASSWORD=fooin compose.env, the ClickHouse server gets configured with that password but the loader does not — its flat-env layer only readsDFE_LOADER_*prefixed vars, soCLICKHOUSE_PASSWORDis silently ignored and the loader falls back to the hard-codeddefaultuser with empty password. Auth then fails for any non-default password setup. This PR letsloader.yamlreference env vars directly (password: env:CLICKHOUSE_PASSWORD), matching the pattern dfe-fetcher already uses for AWS/GCP/M365/Azure credentials.Field types — no breaking changes
The YAML-deser
ClickHouseConfigatsrc/config/loader.rs:120-130already haspassword: SensitiveString. The internal client struct atsrc/clickhouse/config.rskeepspassword: String. TheFromimpl atloader.rs:146-167bridges them; resolution happens on the YAML struct before that bridge runs.Dependencies
resolve()from dfe-fetcher into shared module hyperi-rustlib#42 — the rustlibcredentialmodule must merge and be released before this PR's CI can pass.This feature is structurally complete and library-level tested, but cannot resolve credentials in production until hyperi-io/hyperi-rustlib#41 is fixed. That rustlib bug (
SensitiveString::serializereturning the literal***REDACTED***string) destroys the YAML password value during this repo'sapply_figment_envserde round-trip — the resolver then sees***REDACTED***instead of the original spec.Diagnostic: temporarily swapping
password: SensitiveString→password: Stringconfirmsmake devruns end-to-end and the credential resolver works as designed. Reverted before commit; see comment on #56 for the full trace.Suggested merge order: rustlib#41 (SensitiveString fix) → rustlib#42 (credential extraction, ideally same release) → cut rustlib release → dfe-fetcher#26 (rustlib version bump + credential adoption) → this PR (rustlib version bump + bin-crate path fix already on this branch).
Commits
ef4c29b— Phase 3 implementation (resolver + module wiring + example config + Cargo.toml feature)e64515e— fix: bin-crate path (crate::config::credentials→dfe_loader::config::credentials) —main.rsis a separate binary crate, socrate::does not reach the lib.Test plan
cargo test --lib config::credentials→ 4/4 (literal pass-through, env resolved, missing-env clear error, vault-without-featureVaultUnsupported)cargo test --lib→ 1183/1183 passcargo clippy --lib -- -D warningscleanmake dev(dfe-docker) builds the loader container against this branch + local rustlib path override; container starts cleanly with the diagnostic-onlySensitiveString → Stringpatch applied (proves the resolver path works)