fix(deployments): validate environment variable names used in Docker commands

Reject names that are not portable identifiers before a deployment starts
and when Docker flags are built. Quote the full KEY=value assignment for
docker run -e flags, and declare generated Dockerfile ARGs as keys only.
This commit is contained in:
Andras Bacsai
2026-09-21 15:42:12 +02:00
parent 19f0ae9a7d
commit 17ca63ff4c
6 changed files with 188 additions and 52 deletions
@@ -50,25 +50,29 @@ it('allows Docker-compatible environment variable keys on the model', function (
expect($env->key)->toBe($key);
})->with([
'starts with digit' => '1BAD',
'hyphen' => 'BAD-KEY',
'letters and underscore' => 'APP_ENV',
'dot' => 'node.name',
'uppercase dots' => 'XPACK.SECURITY.ENABLED',
'semicolon' => 'BAD;KEY',
]);
it('rejects environment variable keys Docker cannot represent on the model', function () {
it('rejects environment variable keys Docker cannot represent on the model', function (string $key) {
$env = new EnvironmentVariable;
expect(function () use ($env) {
$env->key = 'BAD=KEY';
})->toThrow(InvalidArgumentException::class, 'Docker-compatible');
});
expect(function () use ($env, $key) {
$env->key = $key;
})->toThrow(InvalidArgumentException::class, 'must start with a letter or underscore');
})->with([
'equals' => 'BAD=KEY',
'starts with digit' => '1BAD',
'hyphen' => 'BAD-KEY',
'semicolon' => 'BAD;KEY',
'command substitution' => 'BAD$(id)',
]);
it('rejects shared environment variable keys Docker cannot represent on the model', function () {
$env = new SharedEnvironmentVariable;
expect(function () use ($env) {
$env->key = 'BAD=KEY';
})->toThrow(InvalidArgumentException::class, 'Docker-compatible');
})->toThrow(InvalidArgumentException::class, 'must start with a letter or underscore');
});