Signal Forge ADR-006: Fail-fast on missing secrets
Status: Accepted
Decision: Services throw at startup if required connection strings are absent or empty. No fallback to defaults.
Code pattern (.NET):
var connStr = builder.Configuration.GetConnectionString("DefaultConnection");
if (string.IsNullOrWhiteSpace(connStr))
throw new InvalidOperationException(
"ConnectionStrings:DefaultConnection is required. Set the environment variable.");
Rationale:
- A service that starts without a database connection appears healthy to liveness probes but fails all requests. This is worse than failing loudly at startup — it makes root cause harder to find.
- Fail-fast produces a clear error in pod logs immediately, the pod enters
CrashLoopBackOff, and the operator can read the exact missing variable fromkubectl describe pod. - Silent defaults (e.g. connecting to
localhost:3306) work in developer machines but break in Kubernetes where there is no local database — this class of environment-specific bugs is eliminated.
Alternative considered: Fallback defaults — rejected because they hide misconfiguration.
This complements secretKeyRef for all credentials: that ADR governs how credentials are stored and referenced; this one governs what happens when a required one is absent.