DNS-Token bei Bedarf sicher aus Vault-Cache nachladen

This commit is contained in:
sascha 2026-08-14 10:32:46 +02:00
parent 428398991b
commit 3ba6001c83

7
app.py
View file

@ -1557,9 +1557,10 @@ async def caddy_site_remove(hostname: str, _=Depends(_verify), dry_run: bool = Q
async def _hetzner_zone_and_rrsets(zone_name: str):
token = _read("HETZNER_DNS_TOKEN")
if not token:
raise HTTPException(503, "HETZNER_DNS_TOKEN unavailable in Butler vault cache")
try:
token = await asyncio.to_thread(_get_hetzner_dns_token)
except RuntimeError as exc:
raise HTTPException(503, str(exc))
headers = {"Authorization": f"Bearer {token}"}
async with httpx.AsyncClient(timeout=30) as client:
zones_response = await client.get(f"{HETZNER_DNS_API}/zones", headers=headers, params={"name": zone_name})