techlite/coolify-deploy-curl
1.0.3
privilege highcurl e jq sobre alpine, com o token fora de argv
implementation
How to choose it
implementation: techlite/coolify-deploy-curlIt satisfies the contracttechlite/coolify-deploy^1.0.0 → 1.1.0
A API do Coolify é HTTP com bearer token, então a implementação de referência é a mais direta possível: `curl` e `jq`, cinco megabytes de imagem, nenhum SDK a acompanhar versão.
O cuidado que não é óbvio: o token nunca aparece em `argv`. Ele vai num arquivo de configuração do curl criado com `umask 077`, porque `-H "Authorization: Bearer ..."` seria visível em `ps` e em qualquer log que ecoe a linha de comando.
What actually runs
- Image
ghcr.io/techlitebr/oren-coolify-deploy-curl:1.0.3
Where the dependencies appear
Inside the container. This is what a compatible worker has to expect — knowing it asks for a credential is not knowing where it reads it.
| dependency | where | |
|---|---|---|
coolifyToken | $COOLIFY_TOKENas an environment variable |