feat(server): enhance secret management and logging functionality

- Added SCRUNNER_SECRETS_KEY to README as a required variable for production.
- Implemented redaction of sensitive information in logs across various components.
- Enhanced script execution functions to include an owner parameter for better secret management.
- Introduced a secrets API in the script sandbox for retrieving and managing secrets.
- Updated UI components to support owner selection for script execution and secret management.
This commit is contained in:
2026-08-14 22:11:03 +07:00
parent 94aa5b2efa
commit 3e4d5f443d
19 changed files with 886 additions and 39 deletions
+2 -1
View File
@@ -35,6 +35,7 @@ The first account created becomes **admin**. Later accounts are created from Use
| Variable | Default | Notes |
|---|---|---|
| `SCRUNNER_JWT_SECRET` | `scrunner-dev-secret` (dev only) | **Required in production** |
| `SCRUNNER_SECRETS_KEY` | `scrunner-dev-secrets-key` (dev only) | Master key for named secrets. **Required in production**. Changing it makes existing secrets unreadable. 64 hex chars are used as a raw AES-256 key; any other string is derived with scrypt. |
| `SCRUNNER_DB_PATH` | `packages/server/data/scrunner.db` | SQLite file |
| `SCRUNNER_LOG_LEVEL` | `debug` | Pino level |
| `SCRUNNER_RETENTION_DAYS` | `30` | Run history prune |
@@ -47,7 +48,7 @@ The first account created becomes **admin**. Later accounts are created from Use
```bash
pnpm install
pnpm build
SCRUNNER_JWT_SECRET=... NODE_ENV=production pnpm start
SCRUNNER_JWT_SECRET=... SCRUNNER_SECRETS_KEY=... NODE_ENV=production pnpm start
```
The server serves `packages/web/dist` when that folder exists.