security: remove hardcoded cluster.local URLs from source code
- activity/memory.go: read MEMORY_SERVICE_URL from env, default localhost - pkg/db/db.go: remove cluster.local from DSN comment - Fix memory_test.go env var name to match
This commit is contained in:
+2
-2
@@ -92,9 +92,9 @@ func RetrieveMemoryActivity(ctx context.Context, in RetrieveMemoryInput) (Retrie
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Get memory service URL and token
|
// Get memory service URL and token
|
||||||
baseURL := os.Getenv("POIMEN_MEMORY_URL")
|
baseURL := os.Getenv("MEMORY_SERVICE_URL")
|
||||||
if baseURL == "" {
|
if baseURL == "" {
|
||||||
baseURL = "http://poimen-memory.poimen.svc.cluster.local:8080"
|
baseURL = "http://localhost:8080"
|
||||||
}
|
}
|
||||||
|
|
||||||
token := os.Getenv("POIMEN_MEMORY_TOKEN")
|
token := os.Getenv("POIMEN_MEMORY_TOKEN")
|
||||||
|
|||||||
@@ -39,7 +39,7 @@ func TestRetrieveMemoryActivity_Query(t *testing.T) {
|
|||||||
defer server.Close()
|
defer server.Close()
|
||||||
|
|
||||||
// Set env for test
|
// Set env for test
|
||||||
t.Setenv("POIMEN_MEMORY_URL", server.URL)
|
t.Setenv("MEMORY_SERVICE_URL", server.URL)
|
||||||
|
|
||||||
output, err := RetrieveMemoryActivity(context.Background(), RetrieveMemoryInput{
|
output, err := RetrieveMemoryActivity(context.Background(), RetrieveMemoryInput{
|
||||||
Query: "security scanning",
|
Query: "security scanning",
|
||||||
@@ -93,7 +93,7 @@ func TestRetrieveMemoryActivity_Context(t *testing.T) {
|
|||||||
}))
|
}))
|
||||||
defer server.Close()
|
defer server.Close()
|
||||||
|
|
||||||
t.Setenv("POIMEN_MEMORY_URL", server.URL)
|
t.Setenv("MEMORY_SERVICE_URL", server.URL)
|
||||||
|
|
||||||
output, err := RetrieveMemoryActivity(context.Background(), RetrieveMemoryInput{
|
output, err := RetrieveMemoryActivity(context.Background(), RetrieveMemoryInput{
|
||||||
Query: "security scan repo",
|
Query: "security scan repo",
|
||||||
|
|||||||
+1
-1
@@ -17,7 +17,7 @@ type DB struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// New creates a new database connection to memory-db (K8s CNPG)
|
// New creates a new database connection to memory-db (K8s CNPG)
|
||||||
// Expected DSN format: postgresql://app:password@memory-db-rw.poimen.svc.cluster.local:5432/memory?sslmode=disable
|
// Expected DSN format: postgresql://app:password@host:5432/dbname?sslmode=disable
|
||||||
func New(dsn string) (*DB, error) {
|
func New(dsn string) (*DB, error) {
|
||||||
if dsn == "" {
|
if dsn == "" {
|
||||||
// Fallback: try to construct from K8s env vars
|
// Fallback: try to construct from K8s env vars
|
||||||
|
|||||||
Reference in New Issue
Block a user