Skip to content

feat(pbs): load relay headers from a secret file or env var - #498

Merged
JasonVranek merged 2 commits into
mainfrom
feat/relay-header-secrets
Sep 14, 2026
Merged

JasonVranek merged 2 commits into
mainfrom
feat/relay-header-secrets

Conversation

@JasonVranek

Copy link
Copy Markdown
Collaborator

Summary

A relay's custom headers, which is how a relay X-Api-key is supplied, can now come from a secret file or an environment variable instead of the config file:

headers = { X-Api-Key = { file = "/run/secrets/relay-key" } }
# or: headers = { X-Api-Key = { env = "RELAY_API_KEY" } }
# or: headers = { X-Api-Key = "literal" }   # unchanged

The value is read when the relay client is built, at startup and on every config reload, so a rotated secret is picked up by a reload.

Header values are marked sensitive so they never appear in debug output, and a literal never appears in the config's Debug. A header loaded from a secret logs its source and a 4-byte fingerprint of the value, never the value, so a rotation is visible across reloads.

commit-boost init mounts every file path read-only into the PBS container at the same path and passes every env variable through from the compose environment, for default and mux relays alike. A relative or missing file fails init rather than producing a compose file docker fills with a root-owned directory.

@JasonVranek
JasonVranek requested a review from a team September 11, 2026 02:44
Comment thread crates/cli/src/docker_init.rs
@JasonVranek
JasonVranek force-pushed the feat/relay-header-secrets branch from f1de14f to eb3551f Compare September 14, 2026 15:25
@JasonVranek
JasonVranek merged commit 3b0b051 into main Sep 14, 2026
4 checks passed
@JasonVranek
JasonVranek deleted the feat/relay-header-secrets branch September 14, 2026 15:25
JasonVranek added a commit that referenced this pull request Oct 2, 2026
…secrets, rustls bump

Brings in #502 (submit-block relay error logging), the v0.11.0-rc2/rc3
releases with the rustls advisory bump, relay headers read from a secret
file or env var (#498), and the ws stream metrics endpoint (#499).

Conflict resolutions:
- relay.rs: kept epbs's relay_headers() helper, shared by the HTTP client
  and the stream handshake, and moved main's header resolution into it
  (HeaderSource literal/file/env, sensitive values, the secret-source log
  line). Its error messages now format the key, which epbs's did not.
- config/pbs.rs: one test module holding epbs's unknown-[pbs]-field tests
  and main's header-source tests.
- config/utils.rs: main's RELAY_URL test constant in test_env.
- Cargo.lock: main's lockfile, plus only what epbs adds.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants