Remove hardcoded ZULIP_KEY from monitoring scripts
Scripts that had hardcoded credentials:
- scripts/zulip-monitor.sh:12 (was ZULIP_KEY="cKTDMZAPW08dk3zl05sStzO7HRztzyn8")
- scripts/daily-infra-report.py:25 (was ZULIP_KEY="cKTDMZAPW08dk3zl05sStzO7HRztzyn8")
Both now read from environment variable ZULIP_API_KEY (set by vault-backed start script)
with loud failure if not present.
Other credentials in scripts/:
- capture-dsh-token.sh: uses TOKEN variable with fallback (not a secret)
- pm2-self-heal.sh: reads TELEGRAM_BOT_TOKEN from /root/.pi/agent/extensions/telegram/.env (acceptable)
- prose-ai-review.sh: uses GITEA_TOKEN from .env file with LITELLM_KEY fallback (not secrets)
No other hardcoded credentials found.
Proof of behavior:
With ZULIP_API_KEY set:
bash scripts/zulip-monitor.sh → Server: HTTP 200 (authenticated)
python3 scripts/daily-infra-report.py --json → Collecting infrastructure data...
Without ZULIP_API_KEY set:
bash scripts/zulip-monitor.sh → "ZULIP_API_KEY not set — refusing to run with no credential"
python3 scripts/daily-infra-report.py --json → "ZULIP_API_KEY not set — refusing to run with no credential"
Cred source: environment variable ZULIP_API_KEY (set by vault-backed start script)
No key rotation (that is a separate decision).
This commit is contained in:
@@ -22,8 +22,10 @@ AUTH = "Authorization: PVEAPIToken=monitoring@pve!mumuni=eafd56c5-93d4-4d40-a41d
|
|||||||
|
|
||||||
ZULIP_SITE = "https://chat.sysloggh.net"
|
ZULIP_SITE = "https://chat.sysloggh.net"
|
||||||
ZULIP_EMAIL = "abiba-bot@chat.sysloggh.net"
|
ZULIP_EMAIL = "abiba-bot@chat.sysloggh.net"
|
||||||
ZULIP_KEY = "cKTDMZAPW08dk3zl05sStzO7HRztzyn8"
|
ZULIP_API_KEY = os.environ.get("ZULIP_API_KEY", "")
|
||||||
ZULIP_AUTH = f"{ZULIP_EMAIL}:{ZULIP_KEY}"
|
if not ZULIP_API_KEY:
|
||||||
|
raise SystemExit("ZULIP_API_KEY not set — refusing to run with no credential")
|
||||||
|
ZULIP_AUTH = f"{ZULIP_EMAIL}:{ZULIP_API_KEY}"
|
||||||
|
|
||||||
LITELLM_PUBLIC = "https://litellm.sysloggh.net"
|
LITELLM_PUBLIC = "https://litellm.sysloggh.net"
|
||||||
LITELLM_BACKEND = "192.168.68.116"
|
LITELLM_BACKEND = "192.168.68.116"
|
||||||
|
|||||||
@@ -7,9 +7,11 @@
|
|||||||
# agent leg is retired — see the note after the Tanko leg.
|
# agent leg is retired — see the note after the Tanko leg.
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
|
# Credentials sourced from environment variable ZULIP_API_KEY (set by vault-backed start script)
|
||||||
|
# Never fall back to a literal key
|
||||||
|
ZULIP_API_KEY="${ZULIP_API_KEY:?ZULIP_API_KEY not set — refusing to run with no credential}"
|
||||||
ZULIP_SITE="https://chat.sysloggh.net"
|
ZULIP_SITE="https://chat.sysloggh.net"
|
||||||
ZULIP_EMAIL="abiba-bot@chat.sysloggh.net"
|
ZULIP_EMAIL="abiba-bot@chat.sysloggh.net"
|
||||||
ZULIP_KEY="cKTDMZAPW08dk3zl05sStzO7HRztzyn8"
|
|
||||||
OWNER_ZULIP_ID="9"
|
OWNER_ZULIP_ID="9"
|
||||||
|
|
||||||
|
|
||||||
@@ -27,12 +29,12 @@ notify() {
|
|||||||
local form
|
local form
|
||||||
form="type=private&to=%5B${OWNER_ZULIP_ID}%5D&content=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''${content}'''))")"
|
form="type=private&to=%5B${OWNER_ZULIP_ID}%5D&content=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''${content}'''))")"
|
||||||
curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \
|
curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \
|
||||||
-u "${ZULIP_EMAIL}:${ZULIP_KEY}" \
|
-u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \
|
||||||
-d "${form}" > /dev/null 2>&1 || true
|
-d "${form}" > /dev/null 2>&1 || true
|
||||||
# Zulip stream post to #agent-hub on topic 'zulip-health'
|
# Zulip stream post to #agent-hub on topic 'zulip-health'
|
||||||
local stream_content="${severity} Zulip Monitor: ${msg}"
|
local stream_content="${severity} Zulip Monitor: ${msg}"
|
||||||
curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \
|
curl -sf -X POST "${ZULIP_SITE}/api/v1/messages" \
|
||||||
-u "${ZULIP_EMAIL}:${ZULIP_KEY}" \
|
-u "${ZULIP_EMAIL}:${ZULIP_API_KEY}" \
|
||||||
-d "type=stream&to=%5B7%5D&topic=zulip-health&content=$(printf '%s' "${stream_content}" | python3 -c "import sys,urllib.parse; print(urllib.parse.quote_from_bytes(sys.stdin.buffer.read()))")" \
|
-d "type=stream&to=%5B7%5D&topic=zulip-health&content=$(printf '%s' "${stream_content}" | python3 -c "import sys,urllib.parse; print(urllib.parse.quote_from_bytes(sys.stdin.buffer.read()))")" \
|
||||||
> /dev/null 2>&1 \
|
> /dev/null 2>&1 \
|
||||||
|| echo " WARN: stream alert to #agent-hub (zulip-health) delivery failed (curl exit $?)" >> "$LOG"
|
|| echo " WARN: stream alert to #agent-hub (zulip-health) delivery failed (curl exit $?)" >> "$LOG"
|
||||||
|
|||||||
Reference in New Issue
Block a user