Learning paths / Deploy on ComputeSphere / Configuration and secrets

Lab: variables and secrets

Verified lab · 20 min · Module 4, lesson 3 of 425 min left in this module

Module 4 · Configuration and secretsLesson 3 of 4

Self-checked for now. Automatic checking arrives with sign-in; until then, tick off each item under Check your work yourself.

Goal: Give a running service a variable and a secret, apply them, and prove the app sees both.

You need csph signed in, with your lab project and environment as defaults (lesson 5.1.1).

  1. Deploy the sample API

    csph deploy --image quay.io/computesphere/learn-sample-api:1.0.0 --name sample-api --port 8080
    

    Its GET /hello returns the GREETING variable and whether API_KEY is set, never the key itself.

    You should seecsph prints Running and your sample-api URL.

  2. See the defaults

    curl https://<your-sample-api-url>/hello
    
    {"api_key_set":false,"message":"Hello, world"}
    

    You should seeJSON with api_key_set false and message Hello, world.

  3. Add the variable and the secret

    Open sample-api, go to Settings, and in Environment variables choose Edit on the General tab. Add GREETING = Hello from ComputeSphere, Save, and choose Save only. On the Secrets tab, choose Edit, add API_KEY with a made-up value, Save, and choose Save & redeploy: one rollout applies both.

    You should seesample-api stays Running while the new version rolls out. Give it a minute before the next step.

  4. Call it again

    Once it's Running:

    curl https://<your-sample-api-url>/hello
    
    {"api_key_set":true,"message":"Hello from ComputeSphere"}
    

    You should seeJSON with api_key_set true and message Hello from ComputeSphere.

  5. See what others can see

    Back in Settings, compare the two tabs. csph services secrets list --service <service-id> prints the secret's name and nothing else.

    You should seeThe variable's value in full; the secret as its name and dots.

Check your work

  • If this doesn't pass

    Names are case-sensitive. GREETING belongs on the General tab, API_KEY on the Secrets tab.

  • If this doesn't pass

    You chose Save only and didn't redeploy afterwards. Choose Redeploy on sample-api. Restart isn't enough (lesson 5.4.2).

  • If this doesn't pass

    Still Hello, world: the value is saved but not running yet, so redeploy. No answer at all: read the deploy log (lesson 5.1.3).

In the docs