kreiling.io
I’d like to discuss how to manually load Elixir configuration files at runtime.
Macro Intent
I want to load an elixir config file (something that looks like, for example, config/config.exs) at runtime, and load that into the application configuration.
Micro Intent
Ultimately, I want to write a Config.Provider implementation which fetches the contents of a secret stored in AWS secrets manager. I’d like for those contents to be an Elixir script with import Config at the top, followed by configuration defined the same way you would in a project’s config/config.exs file. I then want to load that configuration into the current (running!) application’s configuration.
Questions & Discussion
- Let’s assume that I can load the secret configuration file from anywhere into a binary with an arbitrary
Config.Providerimplementation (ignore SecretsManager for now). How would I go about compiling it and loading it into the application configuration? - What do you think of this approach to secret management, at least in theory?
- What (at least roughly) do you do for secret management in your Elixir and/or Phoenix applications?
My Take
Let’s consider an alternative Config.Provider implementation: instead load a YAML file, parse it, and translate it into a keyword list to merge into the current config. In my eyes that has a few downsides that I dislike:
- Added dependency on a YAML parser
- Designing how that YAML is structured is not a trivial task
- It’s a roundabout way to get to what I ultimately want, which is just to load configuration from a remote location into the current node’s application configuration.
These are my thoughts. Let me know yours!
Trending in Questions
Other Trending Topics
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixirconf-us
- #blog-post
- #ai
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #hex
- #security
- #metaprogramming










Showing Posts 1 to 10- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
factoryd
We run in ECS and use param store for our secrets. You can simply set environment variables in your task definition under secrets.
from there I put them in
prod.exsas configuration.I know
valueFromsupports secret manager too.EDIT: Pass sensitive data to an Amazon ECS container - Amazon Elastic Container Service
kreiling.io
I believe your solution is more common and simpler than the example I gave. However, this is similar to my third point of what I dislike about alternatives; it’s a roundabout way to load secrets into your application. You have to have an intermediary step between fetching that configuration and loading it; in your case, it’s having to configure those variable names in ECS and then extract them in your application configuration.
factoryd
I don’t think you’ll find a magic bullet here. You have to do the work somewhere. And in the case of Config, it’s a compile-time concern. If you want runtime config, you have to write the code or do something similar to what I explained.
kreiling.io
Rarely in programming would I argue that anything is a magic bullet - there are tradeoffs in every decision we make! I’m just looking for a discussion about this idea I had and why/how I should/shouldn’t do it.
Sorry, I should have made myself clearer: I’m running this application in production as an Elixir release. Therefore I can write a custom
Config.Providerto load application configuration at runtime. Do you happen to build and run your application(s) as an Elixir release?factoryd
Oh I’m willing to brainstorm. I’m completely isolated and bored just like you!
I do run as a release.
I actually just created a toy app to investigate possibilities right now.
kreiling.io
So I’ve thought about it some more and looked at some docs in the
Codemodule and there’s a warning about evaluating code coming from the network. Dang, seems like loading data from SecretsManager would be a bad idea from a security perspective…Still - could there be another way??
I want to see if it’s possible. My current solution would be to have the config provider do:
factoryd
I have the same idea
and then load with a json file:
like
I believe this would work and is totally feasible.
…and I may just start using this instead of task definition secrets!
EDIT: Fixed the duplicate issue
factoryd
Ohhh!
I think I understand your question in more detail now. You want to actually store the config file in secrets manager and eval it! I don’t think I would try that. Seems odd to me.
kreiling.io
Yeah… The security concern is what makes me want to avoid it. Using dynamic code loading in a sandboxed environment for, say, integration tests, can be really useful. But… doing the same thing in a production environment - with data from a remote source - probably isn’t a good idea.
Yes yes yes, you’re exactly right! The
rel/releases.exsfile is super useful for loading some information at boot-time, but it’s packaged in with the release. Essentially what I’m looking for is to fetch that file from a remote source at boot-time!factoryd
I’ve been thinking about this.
Since you trust yourself, and therefore your own code, I think if you ditch the Mix.Config stuff, and just define a keyword list, you will be able to safely eval the code using your config provider.