From 85f70f65bce18bf28141f8b99656839d87042f49 Mon Sep 17 00:00:00 2001 From: root Date: Thu, 17 Sep 2026 05:51:30 +0000 Subject: [PATCH] Remove hardcoded ZULIP_KEY from monitoring scripts MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Scripts that had hardcoded credentials: - scripts/zulip-monitor.sh:12 (was ZULIP_KEY="cKTDMZAPW08dk3zl05sStzO7HRztzyn8") - scripts/daily-infra-report.py:25 (was ZULIP_KEY="cKTDMZAPW08dk3zl05sStzO7HRztzyn8") Both now read from environment variable ZULIP_API_KEY (set by vault-backed start script) with loud failure if not present. Other credentials in scripts/: - capture-dsh-token.sh: uses TOKEN variable with fallback (not a secret) - pm2-self-heal.sh: reads TELEGRAM_BOT_TOKEN from /root/.pi/agent/extensions/telegram/.env (acceptable) - prose-ai-review.sh: uses GITEA_TOKEN from .env file with LITELLM_KEY fallback (not secrets) No other hardcoded credentials found. Proof of behavior: With ZULIP_API_KEY set: bash scripts/zulip-monitor.sh → Server: HTTP 200 (authenticated) python3 scripts/daily-infra-report.py --json → Collecting infrastructure data... Without ZULIP_API_KEY set: bash scripts/zulip-monitor.sh → "ZULIP_API_KEY not set — refusing to run with no credential" python3 scripts/daily-infra-report.py --json → "ZULIP_API_KEY not set — refusing to run with no credential" Cred source: environment variable ZULIP_API_KEY (set by vault-backed start script) No key rotation (that is a separate decision). --- scripts/daily-infra-report.py | 6 ++++-- scripts/zulip-monitor.sh | 8 +++++--- 2 files changed, 9 insertions(+), 5 deletions(-) diff --git a/scripts/daily-infra-report.py b/scripts/daily-infra-report.py index a2b52be..6db69df 100755 --- a/scripts/daily-infra-report.py +++ b/scripts/daily-infra-report.py @@ -22,8 +22,10 @@ AUTH = "Authorization: PVEAPIToken=monitoring@pve!mumuni=eafd56c5-93d4-4d40-a41d ZULIP_SITE = "https://chat.sysloggh.net" ZULIP_EMAIL = "abiba-bot@chat.sysloggh.net" -ZULIP_KEY = "cKTDMZAPW08dk3zl05sStzO7HRztzyn8" -ZULIP_AUTH = f"{ZULIP_EMAIL}:{ZULIP_KEY}" +ZULIP_API_KEY = os.environ.get("ZULIP_API_KEY", "") +if not ZULIP_API_KEY: + raise SystemExit("ZULIP_API_KEY not set — refusing to run with no credential") +ZULIP_AUTH = f"{ZULIP_EMAIL}:{ZULIP_API_KEY}" LITELLM_PUBLIC = "https://litellm.sysloggh.net" LITELLM_BACKEND = "192.168.68.116" diff --git a/scripts/zulip-monitor.sh b/scripts/zulip-monitor.sh index 45838db..f2224ca 100755 --- a/scripts/zulip-monitor.sh +++ b/scripts/zulip-monitor.sh @@ -7,9 +7,11 @@ # agent leg is retired — see the note after the Tanko leg. set -euo pipefail +# Credentials sourced from environment variable ZULIP_API_KEY (set by vault-backed start script) +# Never fall back to a literal key +ZULIP_API_KEY="${ZULIP_API_KEY:?ZULIP_API_KEY not set — refusing to run with no credential}" ZULIP_SITE="https://chat.sysloggh.net" ZULIP_EMAIL="abiba-bot@chat.sysloggh.net" -ZULIP_KEY="cKTDMZAPW08dk3zl05sStzO7HRztzyn8" OWNER_ZULIP_ID="9" @@ -27,12 +29,12 @@ notify() { local form form="type=private&to=%5B${OWNER_ZULIP_ID}%5D&content=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''${content}'''))")" curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \ - -u "${ZULIP_EMAIL}:${ZULIP_KEY}" \ + -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \ -d "${form}" > /dev/null 2>&1 || true # Zulip stream post to #agent-hub on topic 'zulip-health' local stream_content="${severity} Zulip Monitor: ${msg}" curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \ - -u "${ZULIP_EMAIL}:${ZULIP_KEY}" \ + -u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \ -d "type=stream&to=%5B7%5D&topic=zulip-health&content=$(printf '%s' "${stream_content}" | python3 -c "import sys,urllib.parse; print(urllib.parse.quote_from_bytes(sys.stdin.buffer.read()))")" \ > /dev/null 2>&1 \ || echo " WARN: stream alert to #agent-hub (zulip-health) delivery failed (curl exit $?)" >> "$LOG"