fix(secrets): backend-aware token checks; drop stale file-path assumptions

Post-migration sweep of legacy file-based secret code:
- deploy.py + doctor.py checked for the token *file* → false 'secret not found'
  warnings now that tokens live in the vault; use read_secret (backend-aware)
- drop now-unused SECRETS_DIR imports
- refresh stale docstring/prompt text (${secret} 'reads ~/.castle/secrets' →
  'via the active backend'; SecretsEditor add-prompt)

Kept (legitimate file paths): the bootstrap tier (OPENBAO_* token/unseal,
cloudflared creds dir) + the rendered 0600 env files.
This commit is contained in:
2026-07-07 07:44:20 -07:00
parent 5949543ace
commit 34061d3a68
4 changed files with 12 additions and 11 deletions

View File

@@ -252,7 +252,7 @@ def resolve_env_split(
partitioning lets callers keep secrets out of unit files and process argv
(routing them through a mode-0600 env file) while inlining the rest.
- ``${secret:NAME}`` reads `~/.castle/secrets/NAME`.
- ``${secret:NAME}`` resolves via the active secret backend (file or OpenBao).
- ``${port}`` / ``${data_dir}`` / ``${name}`` / ``${public_url}`` (and
anything else in ``context``) expand to castle's computed values, so a
service maps them to whatever env var its program reads (e.g.