Skip to content

Commit c1aeb19

Browse files
docs(settings): correct the config-precedence docstring (#1542)
The module docstring listed the configuration sources in the wrong order — secrets directories above datajoint.json — contradicting the loader, where _load_secrets only assigns when a value is still unset, so datajoint.json (and env) win over .secrets/. Fix the order to: runtime > env > datajoint.json > .secrets/ > defaults, and state explicitly that the file outranks the secrets directory. Also correct the .secrets/ example: the loader reads database.* and stores.<name>.<attr> files, not aws.secret_access_key. This is the upstream origin of the inverted-precedence docs corrected in datajoint-docs (#258).
1 parent 6147bfd commit c1aeb19

1 file changed

Lines changed: 10 additions & 4 deletions

File tree

‎src/datajoint/settings.py‎

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,17 @@
44
This module provides strongly-typed configuration with automatic loading
55
from environment variables, secrets directories, and JSON config files.
66
7-
Configuration sources (in priority order):
7+
Configuration sources (highest precedence first):
88
9-
1. Environment variables (``DJ_*``)
10-
2. Secrets directories (``.secrets/`` in project, ``/run/secrets/datajoint/``)
9+
1. Runtime assignment (``dj.config[...] = ...``)
10+
2. Environment variables (``DJ_*``)
1111
3. Project config file (``datajoint.json``, searched recursively up to ``.git/.hg``)
12+
4. Secrets directories (``.secrets/`` in project, ``/run/secrets/datajoint/``)
13+
5. Built-in defaults
14+
15+
A value set by a higher source is not overridden by a lower one. In particular
16+
``datajoint.json`` takes precedence over ``.secrets/``: the secrets directory
17+
only supplies values the config file and environment leave unset.
1218
1319
Examples
1420
--------
@@ -30,7 +36,7 @@
3036
├── datajoint.json # Project config (commit this)
3137
├── .secrets/ # Local secrets (gitignore this)
3238
│ ├── database.password
33-
│ └── aws.secret_access_key
39+
│ └── stores.main.secret_key # one file per setting: database.* or stores.<name>.<attr>
3440
└── src/
3541
└── analysis.py # Config found via parent search
3642
"""

0 commit comments

Comments
 (0)