release: harden plugin deployment and recovery
This commit is contained in:
@@ -24,12 +24,14 @@ PLUGIN_CONFIG_KEY=local-development-secret-at-least-32-chars \
|
||||
go run .
|
||||
```
|
||||
|
||||
`PLUGIN_ALLOW_UNSIGNED=true` is a development-only switch. Production
|
||||
packages must contain `signature.json`, use Ed25519, and match a trusted key
|
||||
from `PLUGIN_TRUSTED_PUBLISHERS` (a JSON object of key ID to base64 public
|
||||
key). `PLUGIN_CONFIG_KEY` is required in every environment; use a randomly
|
||||
generated secret in production and keep it stable across restarts so encrypted
|
||||
plugin configuration remains decryptable.
|
||||
`PLUGIN_ALLOW_UNSIGNED=true` is a development-only switch for business package
|
||||
uploads. Production `.s2plugin` packages must contain `signature.json`, use
|
||||
Ed25519, and match a trusted key from `PLUGIN_TRUSTED_PUBLISHERS` (a JSON
|
||||
object of key ID to base64 public key). Plugin Admin itself is deployed as a
|
||||
pinned source checkout and binary, not as a `.s2plugin` package. `PLUGIN_CONFIG_KEY`
|
||||
is required in every environment; use a randomly generated secret in production
|
||||
and keep it stable across restarts so encrypted plugin configuration remains
|
||||
decryptable.
|
||||
|
||||
When the optional subscription module is enabled, set `PLUGIN_PUBLIC_URL` to
|
||||
the externally reachable Plugin Admin base URL (without `/admin`), for example
|
||||
|
||||
Reference in New Issue
Block a user