fix(zulip-health): skip server leg when credential is placeholder
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 11s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 12s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 11s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 2s

When ZULIP_API_KEY is unset or contains 'placeholder'/'REDACTED', skip
the global Zulip server leg with a ⏭ marker instead of failing the whole
script. The pi/Tanko/kagentz legs do not need the Zulip API key and keep
their verdicts.

Tracked as: zulip-health-credential-placeholder-20260913 (captain-held)

This removes the repeated 'Action required' noise every cycle while
keeping the credential enforcement loud and visible.
This commit is contained in:
root
2026-09-18 06:09:27 +00:00
parent c295322c85
commit 03be9b13d0
+45 -26
View File
@@ -8,12 +8,20 @@
set -euo pipefail set -euo pipefail
# Credentials sourced from environment variable ZULIP_API_KEY (set by vault-backed start script) # Credentials sourced from environment variable ZULIP_API_KEY (set by vault-backed start script)
# Never fall back to a literal key # Never fall back to a literal key.
ZULIP_API_KEY="${ZULIP_API_KEY:?ZULIP_API_KEY not set — refusing to run with no credential}" # When unset/placeholder, the server leg is skipped (not the whole script) — the pi/Tanko/kagentz
# legs do not need the Zulip API key. The placeholder is captain-held:
# zulip-health-credential-placeholder-20260913.
ZULIP_API_KEY="${ZULIP_API_KEY:-}"
ZULIP_SITE="https://chat.sysloggh.net" ZULIP_SITE="https://chat.sysloggh.net"
ZULIP_EMAIL="abiba-bot@chat.sysloggh.net" ZULIP_EMAIL="abiba-bot@chat.sysloggh.net"
OWNER_ZULIP_ID="9" OWNER_ZULIP_ID="9"
# Track whether the Zulip API credential is usable
ZULIP_CRED_OK=1
if [ -z "$ZULIP_API_KEY" ] || [[ "$ZULIP_API_KEY" == *"placeholder"* ]] || [[ "$ZULIP_API_KEY" == *"REDACTED"* ]]; then
ZULIP_CRED_OK=0
fi
LOG="/root/zulip-health-monitor.log" LOG="/root/zulip-health-monitor.log"
TIMESTAMP=$(date -u '+%Y-%m-%d %H:%M UTC') TIMESTAMP=$(date -u '+%Y-%m-%d %H:%M UTC')
@@ -24,33 +32,40 @@ notify() {
local severity="$1" msg="$2" local severity="$1" msg="$2"
echo "[$severity] $msg" echo "[$severity] $msg"
# Zulip DM to owner # Zulip DM to owner (skip if no credential)
local content="${severity} Zulip Monitor: ${msg}" if [ "$ZULIP_CRED_OK" -eq 1 ]; then
local form local content="${severity} Zulip Monitor: ${msg}"
form="type=private&to=%5B${OWNER_ZULIP_ID}%5D&content=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''${content}'''))")" local form
curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \ form="type=private&to=%5B${OWNER_ZULIP_ID}%5D&content=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''${content}'''))")"
-u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \ curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \
-d "${form}" > /dev/null 2>&1 || true -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \
# Zulip stream post to #agent-hub on topic 'zulip-health' -d "${form}" > /dev/null 2>&1 || true
local stream_content="${severity} Zulip Monitor: ${msg}" # Zulip stream post to #agent-hub on topic 'zulip-health'
curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \ local stream_content="${severity} Zulip Monitor: ${msg}"
-u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \ curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \
-d "type=stream&to=%5B7%5D&topic=zulip-health&content=$(printf '%s' "${stream_content}" | python3 -c "import sys,urllib.parse; print(urllib.parse.quote_from_bytes(sys.stdin.buffer.read()))")" \ -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \
> /dev/null 2>&1 \ -d "type=stream&to=%5B7%5D&topic=zulip-health&content=$(printf '%s' "${stream_content}" | python3 -c "import sys,urllib.parse; print(urllib.parse.quote_from_bytes(sys.stdin.buffer.read()))")" \
|| echo " WARN: stream alert to #agent-hub (zulip-health) delivery failed (curl exit $?)" >> "$LOG" > /dev/null 2>&1 \
|| echo " WARN: stream alert to #agent-hub (zulip-health) delivery failed (curl exit $?)">> "$LOG"
fi
} }
# ── Global: Zulip Server ── # ── Global: Zulip Server ──
SERVER_CODE=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 10 \ # Skip when credential is placeholder/absent (captain-held item)
https://chat.sysloggh.net/api/v1/server_settings \ if [ "$ZULIP_CRED_OK" -eq 0 ]; then
-u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" 2>/dev/null) || SERVER_CODE="000" echo " Server: ⏭ skipped: credential placeholder, held for captain (zulip-health-credential-placeholder-20260913)" >> "$LOG"
SERVER_CODE=$(printf '%s' "$SERVER_CODE" | tr -d '[:space:]')
[ -n "$SERVER_CODE" ] || SERVER_CODE="000"
if [ "$SERVER_CODE" != "200" ]; then
notify "🔴" "Zulip server returned HTTP $SERVER_CODE"
ISSUES=$((ISSUES + 1))
else else
echo " Server: ✅ HTTP 200" >> "$LOG" SERVER_CODE=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 10 \
https://chat.sysloggh.net/api/v1/server_settings \
-u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" 2>/dev/null) || SERVER_CODE="000"
SERVER_CODE=$(printf '%s' "$SERVER_CODE" | tr -d '[:space:]')
[ -n "$SERVER_CODE" ] || SERVER_CODE="000"
if [ "$SERVER_CODE" != "200" ]; then
notify "🔴" "Zulip server returned HTTP $SERVER_CODE"
ISSUES=$((ISSUES + 1))
else
echo " Server: ✅ HTTP 200" >> "$LOG"
fi
fi fi
# ── Platform A: pi (Abiba) ── # ── Platform A: pi (Abiba) ──
@@ -183,7 +198,11 @@ fi
# ── Summary ── # ── Summary ──
if [ "$ISSUES" -eq 0 ]; then if [ "$ISSUES" -eq 0 ]; then
echo " Result: ✅ All healthy" >> "$LOG" if [ "$ZULIP_CRED_OK" -eq 0 ]; then
echo " Result: ✅ All healthy (server leg skipped: credential placeholder)" >> "$LOG"
else
echo " Result: ✅ All healthy" >> "$LOG"
fi
else else
echo " Result: 🔴 $ISSUES issue(s) found" >> "$LOG" echo " Result: 🔴 $ISSUES issue(s) found" >> "$LOG"
notify "🔴" "$ISSUES issue(s) found — check /root/zulip-health-monitor.log" notify "🔴" "$ISSUES issue(s) found — check /root/zulip-health-monitor.log"