fireproofsocks

fireproofsocks

Configuration Providers vs. a Single Source of Truth: the battle to ensure valid app config

I wanted to solicit the community’s knowledge/experience/recommendations on this one…

Let’s say you’re working with an application that gets deployed to production and you rely on a configuration provider (e.g. secrets_manager_provider | Hex but it doesn’t particularly matter which one).

The problem this solves is that now you can inject sensitive values directly into your Application’s process dictionary. Yay!

However, this creates a new problem: the Application process dictionary no longer has a single source of truth. We don’t know its state! With the introduction of a custom configuration provider, we no longer have a nice mapping from simple config files to Application values.

If we were relying on just runtime.exs, we could easily enforce that certain values be supplied by the environment, e.g.

import Config

config :my_app, :something, System.fetch_env!("SOMETHING")

And that creates a strong contract with the environment: the app will not start unless it is properly configured. This is the approach I leaned into with the dotenvy and it has worked well.

But with a configuration provider, we can’t take the same approach… we might not even use runtime.exs. So we have to move our “defenses” out of the configuration files and retreat into the application itself to verify that our app is configured properly.

Even if our app favors the use of Application.fetch_env!/2 over get_env/3 that’s no guarantee that it has the values it needs when it starts. With the use of the custom configuration provider, we can no longer guarantee that our Application’s process dictionary is in a good state.

How do we defend against this? We could put some code into our app’s start/2 function, e.g. something like:

  @impl true
  def start(_type, _args) do

    Application.fetch_env!(:my_app, :something)  # <-- blow up before start

    children =
      [...]
   # ...

But that feels redundant.

What are other ways to guard against this? Am I missing a trick here? Thanks in advance!

Most Liked

evadne

evadne

For me, a non-issue, just be careful

I’d choose whatever that is clear and rely on the infrastructure & telemetry to roll back bad deploys — for example: if the app does not start and pass health checks within X seconds in Y tries then fail the container.

Unlikely you’d churn configuration 10 times a day or even 10 times a week/month

Last Post!

fireproofsocks

fireproofsocks

Can you say more about that? The problem I’m seeing is that the code that would prevent a bad deploy is in the config files. But when a value enters via a configuration provider, there’s no visibility and no visible code that vets those values.

Where Next?

Popular in Discussions Top

New
AlexMcConnell
The reason that Rails is as popular as it is is because it’s very easy for relatively inexperienced developers to get a lot of work done....
588 20046 166
New
AstonJ
I’ve just started the Phoenix part of the utterly brilliant online course by @pragdave. On generating the Phoenix app he uses the --no-ec...
New
jer
I’ve been using umbrellas for a while, and generally started off (on greenfield projects at least) by isolating subapps based on clearly ...
New
chulkilee
Here are the list of HTTP client libraries/wrappers, and some thoughts on HTTP client in general. I’d like to hear from others how they w...
New
AstonJ
If so I (and hopefully others!) might have some tips for you :slight_smile: But first, please say which area you’re finding most challen...
New
marciol
Please, let me know if this kind of discussion already took place in another topic . Hi all, how do you consider if is better to build ...
New

Other popular topics Top

nobody
Hi! In PHP: $_SERVER[‘SERVER_ADDR’] - in Elixir? Searched the docs for ip address and the web, no good results. Thanks!
New
JakeBecker
TL;DR: I’ve just released an implementation of Microsoft’s IDE-independent Language Server Protocol for Elixir. It adds language support ...
1144 54921 245
New
sen
Hi All, I set a environment variables in dev.exs , like below code. when i start server, how can i set the ${enable} value? thanks. d...
New
axelson
This post is a wiki (feel free to hit the edit button near the bottom right of this post to add your own changes!) This post collects co...
239 49084 226
New
bsollish-terakeet
Credo is smart enough to check for (something like) this: assert length(the_list) == 0 with this response: Checking if an enum is empt...
New
jason.o
In the code below, if the create action is not set to accept “extra_key” as an input, it errors out with a message shown above. Is there ...
New

We're in Beta

About us Mission Statement