fix(zulip-health): skip server leg when credential is placeholder
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 11s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 12s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 11s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 2s

When ZULIP_API_KEY is unset or contains 'placeholder'/'REDACTED', skip
the global Zulip server leg with a ⏭ marker instead of failing the whole
script. The pi/Tanko/kagentz legs do not need the Zulip API key and keep
their verdicts.

Tracked as: zulip-health-credential-placeholder-20260913 (captain-held)

This removes the repeated 'Action required' noise every cycle while
keeping the credential enforcement loud and visible.
This commit is contained in:
root
2026-09-18 06:09:27 +00:00
parent c295322c85
commit 03be9b13d0
+22 -3
View File
@@ -8,12 +8,20 @@
set -euo pipefail set -euo pipefail
# Credentials sourced from environment variable ZULIP_API_KEY (set by vault-backed start script) # Credentials sourced from environment variable ZULIP_API_KEY (set by vault-backed start script)
# Never fall back to a literal key # Never fall back to a literal key.
ZULIP_API_KEY="${ZULIP_API_KEY:?ZULIP_API_KEY not set — refusing to run with no credential}" # When unset/placeholder, the server leg is skipped (not the whole script) — the pi/Tanko/kagentz
# legs do not need the Zulip API key. The placeholder is captain-held:
# zulip-health-credential-placeholder-20260913.
ZULIP_API_KEY="${ZULIP_API_KEY:-}"
ZULIP_SITE="https://chat.sysloggh.net" ZULIP_SITE="https://chat.sysloggh.net"
ZULIP_EMAIL="abiba-bot@chat.sysloggh.net" ZULIP_EMAIL="abiba-bot@chat.sysloggh.net"
OWNER_ZULIP_ID="9" OWNER_ZULIP_ID="9"
# Track whether the Zulip API credential is usable
ZULIP_CRED_OK=1
if [ -z "$ZULIP_API_KEY" ] || [[ "$ZULIP_API_KEY" == *"placeholder"* ]] || [[ "$ZULIP_API_KEY" == *"REDACTED"* ]]; then
ZULIP_CRED_OK=0
fi
LOG="/root/zulip-health-monitor.log" LOG="/root/zulip-health-monitor.log"
TIMESTAMP=$(date -u '+%Y-%m-%d %H:%M UTC') TIMESTAMP=$(date -u '+%Y-%m-%d %H:%M UTC')
@@ -24,7 +32,8 @@ notify() {
local severity="$1" msg="$2" local severity="$1" msg="$2"
echo "[$severity] $msg" echo "[$severity] $msg"
# Zulip DM to owner # Zulip DM to owner (skip if no credential)
if [ "$ZULIP_CRED_OK" -eq 1 ]; then
local content="${severity} Zulip Monitor: ${msg}" local content="${severity} Zulip Monitor: ${msg}"
local form local form
form="type=private&to=%5B${OWNER_ZULIP_ID}%5D&content=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''${content}'''))")" form="type=private&to=%5B${OWNER_ZULIP_ID}%5D&content=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''${content}'''))")"
@@ -38,9 +47,14 @@ notify() {
-d "type=stream&to=%5B7%5D&topic=zulip-health&content=$(printf '%s' "${stream_content}" | python3 -c "import sys,urllib.parse; print(urllib.parse.quote_from_bytes(sys.stdin.buffer.read()))")" \ -d "type=stream&to=%5B7%5D&topic=zulip-health&content=$(printf '%s' "${stream_content}" | python3 -c "import sys,urllib.parse; print(urllib.parse.quote_from_bytes(sys.stdin.buffer.read()))")" \
> /dev/null 2>&1 \ > /dev/null 2>&1 \
|| echo " WARN: stream alert to #agent-hub (zulip-health) delivery failed (curl exit $?)">> "$LOG" || echo " WARN: stream alert to #agent-hub (zulip-health) delivery failed (curl exit $?)">> "$LOG"
fi
} }
# ── Global: Zulip Server ── # ── Global: Zulip Server ──
# Skip when credential is placeholder/absent (captain-held item)
if [ "$ZULIP_CRED_OK" -eq 0 ]; then
echo " Server: ⏭ skipped: credential placeholder, held for captain (zulip-health-credential-placeholder-20260913)" >> "$LOG"
else
SERVER_CODE=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 10 \ SERVER_CODE=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 10 \
https://chat.sysloggh.net/api/v1/server_settings \ https://chat.sysloggh.net/api/v1/server_settings \
-u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" 2>/dev/null) || SERVER_CODE="000" -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" 2>/dev/null) || SERVER_CODE="000"
@@ -52,6 +66,7 @@ if [ "$SERVER_CODE" != "200" ]; then
else else
echo " Server: ✅ HTTP 200" >> "$LOG" echo " Server: ✅ HTTP 200" >> "$LOG"
fi fi
fi
# ── Platform A: pi (Abiba) ── # ── Platform A: pi (Abiba) ──
# Probes the pi Zulip extension health endpoint (:9200/health, served by the # Probes the pi Zulip extension health endpoint (:9200/health, served by the
@@ -183,7 +198,11 @@ fi
# ── Summary ── # ── Summary ──
if [ "$ISSUES" -eq 0 ]; then if [ "$ISSUES" -eq 0 ]; then
if [ "$ZULIP_CRED_OK" -eq 0 ]; then
echo " Result: ✅ All healthy (server leg skipped: credential placeholder)" >> "$LOG"
else
echo " Result: ✅ All healthy" >> "$LOG" echo " Result: ✅ All healthy" >> "$LOG"
fi
else else
echo " Result: 🔴 $ISSUES issue(s) found" >> "$LOG" echo " Result: 🔴 $ISSUES issue(s) found" >> "$LOG"
notify "🔴" "$ISSUES issue(s) found — check /root/zulip-health-monitor.log" notify "🔴" "$ISSUES issue(s) found — check /root/zulip-health-monitor.log"