ODDK v0.1.81
Changed
-
An instance's postgres password is no longer written into its container's
Docker configuration. Docker keepsConfig.Envfor a container's whole
lifetime and hands it to anything that can read container metadata, so the
credential was reachable throughdocker inspect, a backup of
/var/lib/docker, or an observability agent holding a read-only
docker.sockmount. A new cluster is now initialised with a throwaway
password and the real one is set over SQL once it is ready, so what remains
visible authenticates nothing. Recreating a container (instance apply,
switch,update) passes no password at all.This is hygiene, not a closed exposure: anyone who can read that metadata can
alsodocker exec <container> psql -U postgres, which the cluster answers
over its local socket without a password. No action is required.Containers created before this release keep their old value until their next
recreate — clearing it sooner would mean restarting the database purely to
tidy metadata.oddk instance update <name>will do it if you want it gone
now, at the cost of a brief restart. -
A recreate that meets an unexpectedly empty data volume now refuses to start
instead of initialising a fresh empty cluster in place of your data.