From 03be9b13d0d88e2a2d48325fc9dcf75cf2885ee4 Mon Sep 17 00:00:00 2001 From: root Date: Fri, 18 Sep 2026 06:09:27 +0000 Subject: [PATCH] fix(zulip-health): skip server leg when credential is placeholder MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit When ZULIP_API_KEY is unset or contains 'placeholder'/'REDACTED', skip the global Zulip server leg with a ⏭ marker instead of failing the whole script. The pi/Tanko/kagentz legs do not need the Zulip API key and keep their verdicts. Tracked as: zulip-health-credential-placeholder-20260913 (captain-held) This removes the repeated 'Action required' noise every cycle while keeping the credential enforcement loud and visible. --- scripts/zulip-monitor.sh | 71 +++++++++++++++++++++++++--------------- 1 file changed, 45 insertions(+), 26 deletions(-) diff --git a/scripts/zulip-monitor.sh b/scripts/zulip-monitor.sh index 3041b3e..b844c98 100755 --- a/scripts/zulip-monitor.sh +++ b/scripts/zulip-monitor.sh @@ -8,12 +8,20 @@ set -euo pipefail # Credentials sourced from environment variable ZULIP_API_KEY (set by vault-backed start script) -# Never fall back to a literal key -ZULIP_API_KEY="${ZULIP_API_KEY:?ZULIP_API_KEY not set — refusing to run with no credential}" +# Never fall back to a literal key. +# When unset/placeholder, the server leg is skipped (not the whole script) — the pi/Tanko/kagentz +# legs do not need the Zulip API key. The placeholder is captain-held: +# zulip-health-credential-placeholder-20260913. +ZULIP_API_KEY="${ZULIP_API_KEY:-}" ZULIP_SITE="https://chat.sysloggh.net" ZULIP_EMAIL="abiba-bot@chat.sysloggh.net" OWNER_ZULIP_ID="9" +# Track whether the Zulip API credential is usable +ZULIP_CRED_OK=1 +if [ -z "$ZULIP_API_KEY" ] || [[ "$ZULIP_API_KEY" == *"placeholder"* ]] || [[ "$ZULIP_API_KEY" == *"REDACTED"* ]]; then + ZULIP_CRED_OK=0 +fi LOG="/root/zulip-health-monitor.log" TIMESTAMP=$(date -u '+%Y-%m-%d %H:%M UTC') @@ -24,33 +32,40 @@ notify() { local severity="$1" msg="$2" echo "[$severity] $msg" - # Zulip DM to owner - local content="${severity} Zulip Monitor: ${msg}" - local form - form="type=private&to=%5B${OWNER_ZULIP_ID}%5D&content=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''${content}'''))")" - curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \ - -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \ - -d "${form}" > /dev/null 2>&1 || true - # Zulip stream post to #agent-hub on topic 'zulip-health' - local stream_content="${severity} Zulip Monitor: ${msg}" - curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \ - -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \ - -d "type=stream&to=%5B7%5D&topic=zulip-health&content=$(printf '%s' "${stream_content}" | python3 -c "import sys,urllib.parse; print(urllib.parse.quote_from_bytes(sys.stdin.buffer.read()))")" \ - > /dev/null 2>&1 \ - || echo " WARN: stream alert to #agent-hub (zulip-health) delivery failed (curl exit $?)" >> "$LOG" + # Zulip DM to owner (skip if no credential) + if [ "$ZULIP_CRED_OK" -eq 1 ]; then + local content="${severity} Zulip Monitor: ${msg}" + local form + form="type=private&to=%5B${OWNER_ZULIP_ID}%5D&content=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''${content}'''))")" + curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \ + -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \ + -d "${form}" > /dev/null 2>&1 || true + # Zulip stream post to #agent-hub on topic 'zulip-health' + local stream_content="${severity} Zulip Monitor: ${msg}" + curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \ + -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \ + -d "type=stream&to=%5B7%5D&topic=zulip-health&content=$(printf '%s' "${stream_content}" | python3 -c "import sys,urllib.parse; print(urllib.parse.quote_from_bytes(sys.stdin.buffer.read()))")" \ + > /dev/null 2>&1 \ + || echo " WARN: stream alert to #agent-hub (zulip-health) delivery failed (curl exit $?)">> "$LOG" + fi } # ── Global: Zulip Server ── -SERVER_CODE=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 10 \ - https://chat.sysloggh.net/api/v1/server_settings \ - -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" 2>/dev/null) || SERVER_CODE="000" -SERVER_CODE=$(printf '%s' "$SERVER_CODE" | tr -d '[:space:]') -[ -n "$SERVER_CODE" ] || SERVER_CODE="000" -if [ "$SERVER_CODE" != "200" ]; then - notify "🔴" "Zulip server returned HTTP $SERVER_CODE" - ISSUES=$((ISSUES + 1)) +# Skip when credential is placeholder/absent (captain-held item) +if [ "$ZULIP_CRED_OK" -eq 0 ]; then + echo " Server: ⏭ skipped: credential placeholder, held for captain (zulip-health-credential-placeholder-20260913)" >> "$LOG" else - echo " Server: ✅ HTTP 200" >> "$LOG" + SERVER_CODE=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 10 \ + https://chat.sysloggh.net/api/v1/server_settings \ + -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" 2>/dev/null) || SERVER_CODE="000" + SERVER_CODE=$(printf '%s' "$SERVER_CODE" | tr -d '[:space:]') + [ -n "$SERVER_CODE" ] || SERVER_CODE="000" + if [ "$SERVER_CODE" != "200" ]; then + notify "🔴" "Zulip server returned HTTP $SERVER_CODE" + ISSUES=$((ISSUES + 1)) + else + echo " Server: ✅ HTTP 200" >> "$LOG" + fi fi # ── Platform A: pi (Abiba) ── @@ -183,7 +198,11 @@ fi # ── Summary ── if [ "$ISSUES" -eq 0 ]; then - echo " Result: ✅ All healthy" >> "$LOG" + if [ "$ZULIP_CRED_OK" -eq 0 ]; then + echo " Result: ✅ All healthy (server leg skipped: credential placeholder)" >> "$LOG" + else + echo " Result: ✅ All healthy" >> "$LOG" + fi else echo " Result: 🔴 $ISSUES issue(s) found" >> "$LOG" notify "🔴" "$ISSUES issue(s) found — check /root/zulip-health-monitor.log"