Secret runtime tidak di-commit ke Git. Mereka hidup sebagai Kubernetes secrets (dan .env / .env.local lokal untuk developer).
Contoh (nama saja)
| Secret / area | Dipakai oleh |
|---|---|
halort-platform-runtime-env | Surfaces/Platform API (DB, OAuth, JWT, DUITKU_ENV, DUITKU_MERCHANT_CODE, DUITKU_API_KEY, DUITKU_CALLBACK_URL, PAYMENT_PROVIDER_SAAS, QRIS_STATIC_PAYLOAD, QRIS_TOKEN_SECRET, …) — QRIS via make sync-platform-secrets |
halort-web-runtime-env | Surfaces/Marketing Web kontak → notifikasi |
halort-notification-runtime-env | Notifications |
ghcr-io-pull | Semua pull image GHCR |
Helper di halort-infra meliputi make sync-ghcr-pull, make sync-platform-secrets, make sync-notification-secrets. DB platform lokal mungkin memakai npm run sync:platform-db / Docker MariaDB — lihat Architecture/Local Development.
Jangan masukkan nilai kredensial ke vault publik ini; gunakan content/private/ (diabaikan Quartz) untuk catatan pribadi bila perlu — lihat SCHEMA.