Docker Compose: make a Sume webhook receiver refuse an empty secret

Use ${SUME_COM_WEBHOOK_SIGNING_SECRET:?message} in compose.yaml so docker compose stops before the receiver starts, and check again in the app code.

5 min readSume
All posts

Write ${SUME_COM_WEBHOOK_SIGNING_SECRET:?set the Sume signing secret} in the service's environment block. Per the Compose interpolation docs, the colon form returns the value when it is set and non-empty, and otherwise exits with your error message, so an empty secret never reaches the container.

Colon or no colon

An empty secret is dangerous for a verifier: an HMAC computed with an empty key is still a valid HMAC, so an attacker who knows that can sign anything you accept. Refuse it at both layers.

Compose interpolation forms (read 2026-10-04)
SyntaxResult
${VAR:?err}Value if set and non-empty, otherwise exit with error
${VAR?err}Value if set (empty allowed), otherwise exit with error

compose.yaml

Use the colon form. The secret comes from GET /v1/webhooks/signing-secret or the dashboard Webhooks tab, and the name Sume's own worker signs with is SUME_COM_WEBHOOK_SIGNING_SECRET.

services:
  receiver:
    build: ./receiver
    ports:
      - "8080:8080"
    environment:
      SUME_COM_WEBHOOK_SIGNING_SECRET: ${SUME_COM_WEBHOOK_SIGNING_SECRET:?set the Sume signing secret in .env}
    restart: unless-stopped

Where the value lives

Export the variable from your shell or secret manager rather than committing it to the repository. This only protects startup. Add the same refusal in the receiver, as in the signature test recipe.

Reachability

A public HTTPS URL is required for webhook_url; Sume rejects localhost and private addresses. Put a TLS-terminating proxy or tunnel in front of port 8080 for testing.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume