Managed objects

How the seed owns the objects it lists, and how it keeps secrets out

  1. Single-row sections are all or nothing
  2. The file holds no secrets
  3. Managed objects
    1. Removing an object

Single-row sections are all or nothing

ldap and settings are a single row each, so the seed must declare all their fields; the other sections are lists.

A seed that omits a field refuses to start and names it:

Config seed failed, refusing to start : Seed file validation failed :
/settings must have required property 'mail_server'

Declare an empty value explicitly with "" or false. The only optional field is ldap.groupfilter: when omitted, it is left unchanged.

settings covers only the mail fields and the URL; all other settings stay editable.

The file holds no secrets

Each ${VARIABLE} is replaced with that environment variable (on Kubernetes, from a Secret), so the file can live in Git.

A variable that is not set is a fatal error, so a placeholder can never end up stored as a password.

Credentials can also use a secret store (secret_store, secret_ref); vault_path goes away in 8.

Managed objects

An object that comes from the seed is flagged managed:

  • It is enforced on every start, so the file stays authoritative.
  • It is read-only: the API answers 403, and the interface marks it Config seed and disables Edit and Delete.
  • Only the seed can set or clear the flag.

Objects created by hand are never touched, unless the seed declares the same name. That record is then adopted: the declared fields are enforced and it becomes read-only. Adoption is logged as a warning and in the audit trail.

Applying the seed is idempotent: records that already match are left alone, so a restart normally reports 0 updated.

A declared repository whose working tree is missing is cloned again on every start, so a failed first clone is retried. The Repositories row of the Status page shows any repository without a working tree.

Removing an object

Removing an object from the file releases it: the record stays and becomes editable again. Deleting a whole section does the same.

Add prune: true to a list section to delete the managed records the file no longer declares:

credentials:
  prune: true
  items:
    - name: production-db
      # anything else the seed used to manage is deleted

prune never deletes a record created by hand.


Copyright © 2023-2026 AnsibleForms. All rights reserved.

This site uses Just the Docs, a documentation theme for Jekyll.