Gateway: config from env vars #2
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context
Gateway service (see #18). Configuration is injected entirely via env vars
so the same container image works anywhere.
Task
Create
app/config.pyreturning a frozen dataclass, read from env:APPLE_TEAM_ID(10-char team ID, JWTiss)APPLE_KEY_ID(MusicKit key ID, JWTkid)APPLE_KEY_PATH(path to theAuthKey_*.p8private key file)APPLE_SERVICES_ID(MusicKit Services ID / client_id)SERVICE_TOKEN(bearer token the beets plugin uses on/api/v1/*)GATEWAY_DB_PATH(default./gateway.db)GATEWAY_BASE_URL(external https URL of the deployment; used to buildthe login page and callback links)
Fail fast at startup: any missing required var aborts with a clear message
naming the variable (use
sys.exitfrom the app factory or a pydanticSettingswithextra="forbid"; stdlibos.environis fine too — keep itdependency-light).
Acceptance criteria
produces an error mentioning the variable name.
SERVICE_TOKENis never logged or exposed in any response.Done in
coop/apple-music-gateway(commitbe064de):app/config.py— frozenConfigdataclass from env (APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_KEY_PATH, APPLE_SERVICES_ID, SERVICE_TOKEN, GATEWAY_DB_PATH default ./gateway.db, GATEWAY_BASE_URL).load_config()raisesConfigErrornaming every missing var;create_app()sys.exits at startup. SERVICE_TOKEN isrepr=False, never logged or exposed. 13 tests pass (full-env parse, per-var missing-name check, DB-path default, token-never-in-repr, factory fail-fast).