Docker Compose: make a Sume webhook receiver refuse an empty secret
Use ${SUME_COM_WEBHOOK_SIGNING_SECRET:?message} in compose.yaml so docker compose stops before the receiver starts, and check again in the app code.

Write ${SUME_COM_WEBHOOK_SIGNING_SECRET:?set the Sume signing secret} in the service's environment block. Per the Compose interpolation docs, the colon form returns the value when it is set and non-empty, and otherwise exits with your error message, so an empty secret never reaches the container.
Colon or no colon
An empty secret is dangerous for a verifier: an HMAC computed with an empty key is still a valid HMAC, so an attacker who knows that can sign anything you accept. Refuse it at both layers.
| Syntax | Result |
|---|---|
${VAR:?err} | Value if set and non-empty, otherwise exit with error |
${VAR?err} | Value if set (empty allowed), otherwise exit with error |
compose.yaml
Use the colon form. The secret comes from GET /v1/webhooks/signing-secret or the dashboard Webhooks tab, and the name Sume's own worker signs with is SUME_COM_WEBHOOK_SIGNING_SECRET.
services:
receiver:
build: ./receiver
ports:
- "8080:8080"
environment:
SUME_COM_WEBHOOK_SIGNING_SECRET: ${SUME_COM_WEBHOOK_SIGNING_SECRET:?set the Sume signing secret in .env}
restart: unless-stoppedWhere the value lives
Export the variable from your shell or secret manager rather than committing it to the repository. This only protects startup. Add the same refusal in the receiver, as in the signature test recipe.
Reachability
A public HTTPS URL is required for webhook_url; Sume rejects localhost and private addresses. Put a TLS-terminating proxy or tunnel in front of port 8080 for testing.
Sources
Related posts
More in Developers
- Draft with GPT Image 2.5 Flare, finish with Sunburst: a two-pass edit
OpenAI pairs Flare with fast generation and Sunburst with editing precision. A Python two-pass on Sume's Image API that drafts, then refines the first result.
- Dramatiq retry_when for Sume: retry only retryable errors
A Dramatiq actor with retry_when that retries 429 and 5xx but not 402 or 400, and sends one stable Idempotency-Key so a retried Sume submit is not billed twice.
- Dropped connection mid-render: what happens to the Sume job
A dropped connection never cancels a Sume job. Wait again with jobs_wait on the same ids, or read the job status; never resubmit the paid create.
- "Each input_references entry needs image_url.url": the fix
A bare URL string or a missing url in input_references returns 400 invalid_request on Sume. The exact entry shape, reference ceilings per row, a helper.
Written by Sume