Load MINIO_SECURE from env and replace adapter asserts with explicit errors.
Default TLS to enabled for production MinIO setups while keeping local and integration tests on plain HTTP via explicit secure=false configuration. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
co-authored by
Cursor
parent
7991dabdbc
commit
3aa91280ec
@@ -25,6 +25,7 @@ class MinioAdapter(ObjectRepositoryInterface, ConnectionAwareAdapter):
|
||||
access_key_env_var_name: str = "MINIO_ACCESS_KEY"
|
||||
secret_key_env_var_name: str = "MINIO_SECRET_KEY"
|
||||
bucket_env_var_name: str = "MINIO_BUCKET"
|
||||
secure_env_var_name: str = "MINIO_SECURE"
|
||||
chunk_size: int = 5 * 2**20 # 5 MiB
|
||||
connection_name: str = "Minio"
|
||||
|
||||
@@ -35,16 +36,16 @@ class MinioAdapter(ObjectRepositoryInterface, ConnectionAwareAdapter):
|
||||
client: minio.Minio | None = None,
|
||||
) -> None:
|
||||
super().__init__()
|
||||
if client is not None and config is None:
|
||||
raise ValueError("config is required when client is provided")
|
||||
if config is None and client is None:
|
||||
if config is None:
|
||||
if client is not None:
|
||||
raise ValueError("config is required when client is provided")
|
||||
config = MinioConfig.from_env(
|
||||
self.endpoint_env_var_name,
|
||||
self.access_key_env_var_name,
|
||||
self.secret_key_env_var_name,
|
||||
self.bucket_env_var_name,
|
||||
self.secure_env_var_name,
|
||||
)
|
||||
assert config is not None
|
||||
self._config = config
|
||||
self._client_injected = client is not None
|
||||
self._client: minio.Minio | None = client
|
||||
|
||||
@@ -34,11 +34,10 @@ class RedisAdapter(JsonRepositoryInterface, ConnectionAwareAdapter):
|
||||
client: redis.Redis | None = None,
|
||||
) -> None:
|
||||
super().__init__()
|
||||
if client is not None and config is None:
|
||||
raise ValueError("config is required when client is provided")
|
||||
if config is None and client is None:
|
||||
if config is None:
|
||||
if client is not None:
|
||||
raise ValueError("config is required when client is provided")
|
||||
config = RedisConfig.from_env(self.uri_env_var_name)
|
||||
assert config is not None
|
||||
self._config = config
|
||||
self._client_injected = client is not None
|
||||
self._client: redis.Redis | None = client
|
||||
|
||||
@@ -9,6 +9,21 @@ from python_utils import check_env
|
||||
|
||||
from python_repositories.config.dotenv_loader import load_dotenv
|
||||
|
||||
_TRUTHY = frozenset({"1", "true", "yes", "on"})
|
||||
_FALSY = frozenset({"0", "false", "no", "off"})
|
||||
|
||||
|
||||
def _env_bool(name: str, default: bool) -> bool:
|
||||
raw = os.getenv(name)
|
||||
if raw is None:
|
||||
return default
|
||||
normalized = raw.strip().lower()
|
||||
if normalized in _TRUTHY:
|
||||
return True
|
||||
if normalized in _FALSY:
|
||||
return False
|
||||
raise ValueError(f"Invalid boolean value for {name}: {raw!r}")
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class MinioConfig:
|
||||
@@ -18,7 +33,7 @@ class MinioConfig:
|
||||
access_key: str
|
||||
secret_key: str
|
||||
bucket: str
|
||||
secure: bool = False
|
||||
secure: bool = True
|
||||
|
||||
@classmethod
|
||||
def from_env(
|
||||
@@ -27,6 +42,7 @@ class MinioConfig:
|
||||
access_key_env_var_name: str = "MINIO_ACCESS_KEY",
|
||||
secret_key_env_var_name: str = "MINIO_SECRET_KEY",
|
||||
bucket_env_var_name: str = "MINIO_BUCKET",
|
||||
secure_env_var_name: str = "MINIO_SECURE",
|
||||
*,
|
||||
use_dotenv: bool = True,
|
||||
) -> MinioConfig:
|
||||
@@ -45,4 +61,5 @@ class MinioConfig:
|
||||
access_key=str(os.getenv(access_key_env_var_name)),
|
||||
secret_key=str(os.getenv(secret_key_env_var_name)),
|
||||
bucket=str(os.getenv(bucket_env_var_name)),
|
||||
secure=_env_bool(secure_env_var_name, default=True),
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user