docs: add 1password secret injection guide

This commit is contained in:
Christian Krakau-Louis
2026-05-22 21:51:47 +02:00
parent b9bc0d3e4f
commit 77de03d8b5
8 changed files with 117 additions and 12 deletions
+4 -2
View File
@@ -24,7 +24,7 @@ The fastest way to get DMARQ running is to use Docker Compose:
2. **Configure environment variables**
Create a `.env` file in the project root:
Create a `.env` file in the project root. For production, prefer a 1Password-mounted `.env` file; see [Secret Handling with 1Password](secrets.md).
```
# Database Configuration
@@ -130,6 +130,8 @@ volumes:
All configuration in the Docker setup is done via environment variables, either directly in the `docker-compose.yml` file or through a separate `.env` file. See the [Configuration](configuration.md) page for detailed information about all available variables.
For production, store secret values in 1Password Environments and inject them into Compose with a mounted `.env` file or your deployment runner's secret-injection feature. Do not commit `.env` files that contain `SECRET_KEY`, database credentials, IMAP passwords, OAuth secrets, or API tokens.
### Volumes
The Docker Compose setup uses these volumes:
@@ -292,4 +294,4 @@ If you encounter volume mounting problems:
1. Check file permissions on the host
2. Use absolute paths in your volume mappings
3. On Windows, ensure you've enabled Docker file sharing for the relevant drives
3. On Windows, ensure you've enabled Docker file sharing for the relevant drives