job "brickbot2" { datacenters = ["aperture"] type = "service" group "brickbot2" { count = 1 task "brickbot2" { driver = "docker" config { image = "ghcr.io/redbrick/brickbot2:latest" auth { username = "${DOCKER_USER}" password = "${DOCKER_PASS}" } volumes = [ "local/ldap.secret:/etc/ldap.secret:ro", ] } template { destination = "local/ldap.secret" perms = "600" data = "{{ key \"api/ldap/secret\" }}" # this is necessary as the secret has no EOF } template { destination = "local/.env" env = true change_mode = "restart" data = <