diff --git a/docker/files/entrypoint.sh b/docker/files/entrypoint.sh index 55060296..3e0e348a 100755 --- a/docker/files/entrypoint.sh +++ b/docker/files/entrypoint.sh @@ -3,9 +3,6 @@ set -eo pipefail CHATMAIL_INIT_SERVICE_PATH="${CHATMAIL_INIT_SERVICE_PATH:-/lib/systemd/system/chatmail-init.service}" -# Whitelist only the env vars needed by chatmail-init.sh. -# Forwarding all env vars (via printenv) would leak Docker internals, -# orchestrator secrets, and other unrelated variables into systemd. env_vars="MAIL_DOMAIN CMDEPLOY_STAGES CHATMAIL_INI TLS_EXTERNAL_CERT_AND_KEY PATH" sed -i "s||$env_vars|g" "$CHATMAIL_INIT_SERVICE_PATH"