Skip to content

Keep RELAY_INBOUND_SECRET when Railway config is applied - #26

Merged
rvegajr merged 1 commit into
developfrom
chore/iac-inbound-secret
Oct 2, 2026
Merged

rvegajr merged 1 commit into
developfrom
chore/iac-inbound-secret

Conversation

@rvegajr

@rvegajr rvegajr commented Oct 2, 2026

Copy link
Copy Markdown
Member

RELAY_INBOUND_SECRET is now set on development, uat and production. It's a random placeholder until the relay mints the real one, so in the meantime every inbound text is rejected. That's correct, because no number is routed to Coachatron yet. It also closes the spoofing hole: before #25, anyone could post a "text from a coach" to the webhook.

.railway/railway.ts lists web's variables exhaustively, so railway config apply would have deleted the new one. plan showed Delete variable web.RELAY_INBOUND_SECRET. The file now preserves it, and plan says "already up to date" in all three environments.

.railway/README.md now says to add every new web variable to the file as preserve().

🤖 Generated with Claude Code

The web variables in .railway/railway.ts are exhaustive: apply deletes
any it omits. The inbound secret is set on all three environments now,
so the file preserves it, and the README says to add new variables.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@rvegajr
rvegajr merged commit 88eab15 into develop Oct 2, 2026
3 checks passed
rvegajr added a commit that referenced this pull request Oct 2, 2026
…und texts (#27)

Promote develop to staging: one-box email-or-mobile join, signed inbound texts (#24–#26)
rvegajr added a commit that referenced this pull request Oct 2, 2026
… texts (#28)

Promote develop to main: one-box email-or-mobile join, signed inbound texts (#24–#26)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant