Secret runtime tidak di-commit ke Git. Mereka hidup sebagai Kubernetes secrets (dan .env / .env.local lokal untuk developer).

Contoh (nama saja)

Secret / areaDipakai oleh
halort-platform-runtime-envSurfaces/Platform API (DB, OAuth, JWT, DUITKU_ENV, DUITKU_MERCHANT_CODE, DUITKU_API_KEY, DUITKU_CALLBACK_URL, PAYMENT_PROVIDER_SAAS, QRIS_STATIC_PAYLOAD, QRIS_TOKEN_SECRET, …) — QRIS via make sync-platform-secrets
halort-web-runtime-envSurfaces/Marketing Web kontak → notifikasi
halort-notification-runtime-envNotifications
ghcr-io-pullSemua pull image GHCR

Helper di halort-infra meliputi make sync-ghcr-pull, make sync-platform-secrets, make sync-notification-secrets. DB platform lokal mungkin memakai npm run sync:platform-db / Docker MariaDB — lihat Architecture/Local Development.

Jangan masukkan nilai kredensial ke vault publik ini; gunakan content/private/ (diabaikan Quartz) untuk catatan pribadi bila perlu — lihat SCHEMA.

Terkait