2 Commits
Author SHA1 Message Date
tiennm99 47afb85093 fix: close remaining secret leaks, timeout gaps and config blind spots
- Generated service names come only from a URL host, a key=value DSN's
  host=, or a MySQL tcp() address, so a password in a key=value DSN can no
  longer end up in the name printed on every log line.
- connect_timeout is added only to postgres:// and postgresql:// URLs
  (parsed, so it never lands after a fragment) or as a key=value token, never
  glued onto a key=value value containing "://".
- Driver parse errors that quote password fragments (mongo escape errors,
  lib/pq's missing "=" error) are replaced with generic hints.
- MongoDB keeps its client only after a successful connect, so a failed
  connect is not disconnected twice.
- Couchbase gets ready_timeout plus 1 minute to connect, so raising
  ready_timeout takes effect.
- Shutdown waits at most 7 seconds, inside Docker's 10-second grace period.
- Each adapter declares its config keys; unknown keys anywhere in the file,
  including under config, log a warning without blocking start.
2026-10-09 12:36:21 +07:00
tiennm99 0af652953f fix: bound connects, write on start, and tighten config checks
- Each connect attempt, including initialization, times out after 1 minute,
  and PostgreSQL DSNs without connect_timeout get connect_timeout=30, since
  lib/pq honours the context only while dialing.
- A service increments right after connecting, so a restart writes even
  when the interval outlasts the process.
- A config path that is a directory (Docker's stand-in for a missing
  bind-mount source) fails with a clear message.
- Generated service names take the first free suffix, and suffixed names
  are reserved so an explicit name cannot silently collide with them.
- counter_key inside a service's config map is rejected instead of being
  overwritten.
- Unknown keys in the config file log a warning without blocking start.
- A .dockerignore keeps local configs and .env out of the build context.
2026-10-09 11:15:59 +07:00