The image cannot be built: the Dockerfile passes a key #111 refuses #121

Closed
opened 2026-09-08 19:51:25 +00:00 by tiagoagueda · 1 comment
Owner

What happened

Building the image fails at collectstatic:

django.core.exceptions.ImproperlyConfigured: POSTULO_SECRET_KEY is too weak: it is 28
characters and at least 50 are needed.

Found while deploying the test instance. The container already running is untouched — the
build never produced an image — but no instance can be rebuilt or upgraded until this
is fixed.

Why it was not caught

#111 made the production settings refuse a key shorter than 50 characters. Two places pass
a key that is not a real one:

  • .forgejo/workflows/ci.yml passes a long literal, with a comment saying it is long
    enough for security.W009. It still passes.
  • docker/Dockerfile:99 passes build-time-only-not-a-secret — 28 characters. It does not.

CI does not build the image, because building one needs a runner advertising the docker
label and none is registered (#81). So the one check that would have caught this is the one
that has never run, and the refusal landed green.

The fix

The build step needs a key for the length of one command, and it never reaches the image.
A longer literal would satisfy the rule while remaining exactly what its own name says it is
— and would be copied by somebody. Generating a random key for that single command satisfies
the rule for the right reason and cannot be copied anywhere.

Worth stating in the Dockerfile beside it: collectstatic needs a key only because the
settings module insists on one, not because anything it writes is signed with it.

Worth being careful about

The real hole is that the image build is not exercised anywhere. The fix above unblocks
today; #81 is what stops the next version of this happening.

## What happened Building the image fails at `collectstatic`: ``` django.core.exceptions.ImproperlyConfigured: POSTULO_SECRET_KEY is too weak: it is 28 characters and at least 50 are needed. ``` Found while deploying the test instance. The container already running is untouched — the build never produced an image — but **no instance can be rebuilt or upgraded** until this is fixed. ## Why it was not caught #111 made the production settings refuse a key shorter than 50 characters. Two places pass a key that is not a real one: - `.forgejo/workflows/ci.yml` passes a long literal, with a comment saying it is long enough for `security.W009`. It still passes. - `docker/Dockerfile:99` passes `build-time-only-not-a-secret` — 28 characters. It does not. CI does not build the image, because building one needs a runner advertising the `docker` label and none is registered (#81). So the one check that would have caught this is the one that has never run, and the refusal landed green. ## The fix The build step needs *a* key for the length of one command, and it never reaches the image. A longer literal would satisfy the rule while remaining exactly what its own name says it is — and would be copied by somebody. Generating a random key for that single command satisfies the rule for the right reason and cannot be copied anywhere. Worth stating in the Dockerfile beside it: `collectstatic` needs a key only because the settings module insists on one, not because anything it writes is signed with it. ## Worth being careful about The real hole is that the image build is not exercised anywhere. The fix above unblocks today; #81 is what stops the next version of this happening.
tiagoagueda added this to the 0.3.0 milestone 2026-09-08 19:51:25 +00:00
Author
Owner

The Dockerfile now generates its build-time key inline — POSTULO_SECRET_KEY="$(python -c 'import secrets; print(secrets.token_urlsafe(64))')" — instead of carrying a 28-character literal that #111 correctly refuses. A generated key also cannot be the one an instance ends up running, which the literal could have been.

tests/test_image_build.py reads the Dockerfile rather than building it, so the same mistake fails in the ordinary suite in milliseconds instead of on a runner ten minutes in. Proved by a successful rebuild on ragnar.

Shipped in d0cc4c8 on 0.3.0, with main kept level.

The Dockerfile now generates its build-time key inline — `POSTULO_SECRET_KEY="$(python -c 'import secrets; print(secrets.token_urlsafe(64))')"` — instead of carrying a 28-character literal that #111 correctly refuses. A generated key also cannot be the one an instance ends up running, which the literal could have been. `tests/test_image_build.py` reads the Dockerfile rather than building it, so the same mistake fails in the ordinary suite in milliseconds instead of on a runner ten minutes in. Proved by a successful rebuild on ragnar. Shipped in `d0cc4c8` on `0.3.0`, with `main` kept level.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Postulo/postulo#121
No description provided.