security: remove hardcoded cluster.local URLs from source code
- activity/memory.go: read MEMORY_SERVICE_URL from env, default localhost - pkg/db/db.go: remove cluster.local from DSN comment - Fix memory_test.go env var name to match
This commit is contained in:
+2
-2
@@ -92,9 +92,9 @@ func RetrieveMemoryActivity(ctx context.Context, in RetrieveMemoryInput) (Retrie
|
||||
}
|
||||
|
||||
// Get memory service URL and token
|
||||
baseURL := os.Getenv("POIMEN_MEMORY_URL")
|
||||
baseURL := os.Getenv("MEMORY_SERVICE_URL")
|
||||
if baseURL == "" {
|
||||
baseURL = "http://poimen-memory.poimen.svc.cluster.local:8080"
|
||||
baseURL = "http://localhost:8080"
|
||||
}
|
||||
|
||||
token := os.Getenv("POIMEN_MEMORY_TOKEN")
|
||||
|
||||
@@ -39,7 +39,7 @@ func TestRetrieveMemoryActivity_Query(t *testing.T) {
|
||||
defer server.Close()
|
||||
|
||||
// Set env for test
|
||||
t.Setenv("POIMEN_MEMORY_URL", server.URL)
|
||||
t.Setenv("MEMORY_SERVICE_URL", server.URL)
|
||||
|
||||
output, err := RetrieveMemoryActivity(context.Background(), RetrieveMemoryInput{
|
||||
Query: "security scanning",
|
||||
@@ -93,7 +93,7 @@ func TestRetrieveMemoryActivity_Context(t *testing.T) {
|
||||
}))
|
||||
defer server.Close()
|
||||
|
||||
t.Setenv("POIMEN_MEMORY_URL", server.URL)
|
||||
t.Setenv("MEMORY_SERVICE_URL", server.URL)
|
||||
|
||||
output, err := RetrieveMemoryActivity(context.Background(), RetrieveMemoryInput{
|
||||
Query: "security scan repo",
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@ type DB struct {
|
||||
}
|
||||
|
||||
// New creates a new database connection to memory-db (K8s CNPG)
|
||||
// Expected DSN format: postgresql://app:password@memory-db-rw.poimen.svc.cluster.local:5432/memory?sslmode=disable
|
||||
// Expected DSN format: postgresql://app:password@host:5432/dbname?sslmode=disable
|
||||
func New(dsn string) (*DB, error) {
|
||||
if dsn == "" {
|
||||
// Fallback: try to construct from K8s env vars
|
||||
|
||||
Reference in New Issue
Block a user