minor
#29385
The app archetype should automatically generate a standard git-ignored local-credentials overlay (tl_config) by default
Request
The application Maven archetype (tl-archetype-app) should generate, for every new application, a standard, leak-free mechanism for providing developer-local secrets (Trac XML-RPC credentials, database passwords, external API tokens, ...) that must not be committed and that survives application restarts without requiring manual setup each time the application starts.
Motivation
Apps regularly need secrets injected via aliases, e.g.:
<alias>
<entry name="%TRAC_PASSWORD%" value="${env:TRAC_PASSWORD:}"/>
</alias>
With only the ${env:...} default, the value is empty unless an environment variable is present in the launching process. This is fragile:
- A shell launched by a skill, CI, or tool is typically non-interactive and does not source the user’s shell profile, so an “export in .bashrc”-style environment file is not picked up.
- Passing the secret as a -Dkey=value JVM/Maven argument leaks it into the process command line (visible via ` ps`).
There is no out-of-the-box, documented pattern, so every app re-invents (or omits) this, and developers encounter avoidable HTTP 401 / empty-credential failures.
Proven pattern (please make this the archetype default)
TopLogic already supports a configuration overlay via XMLProperties.Setting.CONFIG_FILE (the tl_config system/JNDI property). MultiProperties.pushSystemProperty loads the named file last (so its alias entries override the base configuration) and silently ignores it when absent ("Configuration '...' not found, will be ignored!"), ensuring that a fresh checkout still boots. The property value is only a path, never the secret.
Configuration that worked well in an app:
- .mvn/jvm.config (committed): -Dtl_config=local.conf.xml — a non-secret path pointer, automatically read by Maven on every invocation.
- local.conf.xml (git-ignored): the actual overlay with literal alias values, e.g.
<root>
<alias>
<entry name="%TRAC_USER%" value="..."/>
<entry name="%TRAC_PASSWORD%" value="..."/>
</alias>
</root>
- local.conf.xml.template (committed): documents the file for other checkouts.
- .gitignore: Ignores the actual local.conf.xml file.
- Eclipse startup: uses the same property as an absolute path, -Dtl_config="${workspace_loc:<project>}/local.conf.xml", so it resolves independently of the launch working directory.
Both launch paths (Maven exec:java and the Eclipse com.top_logic.ide.jetty.Bootstrap launch) then read the same single git-ignored file.
Suggested scope
- Archetype generates items 1, 3, and 4 above and the Eclipse startup VM argument (item 5) by default; item 2 is created by the developer from the template.
- Consider including a brief section in the generated README to document this mechanism.
- The specific alias names are application-specific; the archetype should include an empty or example overlay, not any actual alias.
Filed as a follow-up to setting this up manually in an application.