fix(daily-infra-report): missing credentials degrade one leg instead of blacking out the digest #126

Merged
abiba-bot merged 1 commits from fix/daily-health-digest-degraded-credentials-20260921 into master 2026-09-21 11:26:33 +00:00
Owner

Makes a missing credential a labelled degraded leg instead of a blackout of the whole digest.

Problem

scripts/daily-infra-report.py raised SystemExit at import when ZULIP_API_KEY was absent (lines 25-27)
and sys.exit(1) at the mail leg without EMAIL_PASSWORD (lines 674-676), so the captain's 10:30 UTC
daily digest produced no artifact at all on 2026-09-20 and 2026-09-21 — even though email is the
captain-decided destination.

Change (single file, +17/-5)

  • Missing ZULIP_API_KEY → ZULIP_AUTH = None plus a printed credential-missing: ZULIP_API_KEY line,
    instead of SystemExit.
  • Missing EMAIL_PASSWORD → printed credential-missing: EMAIL_PASSWORD line and a labelled degraded
    return, instead of sys.exit(1).
  • End-of-run summary now prints Degraded legs (n) with each leg named, or All legs fully credentialed.
  • for s in (storages or []) in the PVE storage section: pre-existing crash on a None PVE response.

No credential was placed, moved or substituted. The digest must never silently use a key it has not
verified as abiba-bot, and this change does not add such a fallback.

Related: zulip-health-credential-placeholder-20260913 (credential placement held for the captain),
daily-health-digest-delivery-20260920.

cc @abiba

Makes a missing credential a **labelled degraded leg** instead of a blackout of the whole digest. ## Problem `scripts/daily-infra-report.py` raised `SystemExit` at import when `ZULIP_API_KEY` was absent (lines 25-27) and `sys.exit(1)` at the mail leg without `EMAIL_PASSWORD` (lines 674-676), so the captain's 10:30 UTC daily digest produced **no artifact at all** on 2026-09-20 and 2026-09-21 — even though email is the captain-decided destination. ## Change (single file, +17/-5) - Missing `ZULIP_API_KEY` → `ZULIP_AUTH = None` plus a printed `credential-missing: ZULIP_API_KEY` line, instead of `SystemExit`. - Missing `EMAIL_PASSWORD` → printed `credential-missing: EMAIL_PASSWORD` line and a labelled degraded return, instead of `sys.exit(1)`. - End-of-run summary now prints `Degraded legs (n)` with each leg named, or `All legs fully credentialed`. - `for s in (storages or [])` in the PVE storage section: pre-existing crash on a `None` PVE response. No credential was placed, moved or substituted. The digest must never silently use a key it has not verified as `abiba-bot`, and this change does not add such a fallback. Related: zulip-health-credential-placeholder-20260913 (credential placement held for the captain), daily-health-digest-delivery-20260920. cc @abiba
abiba-bot added 1 commit 2026-09-21 11:20:50 +00:00
feat(daily-infra-report): make missing credentials a labelled degraded leg
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 6s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 6s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
ccc916d1ec
- ZULIP_API_KEY: no longer SystemExit, now reports 'credential-missing: ZULIP_API_KEY'
- EMAIL_PASSWORD: no longer sys.exit(1), now appends to DEGRADED_LEGS and returns success
- PVE API: fixed None check in storage section
- Summary: reports degraded legs before summary

This allows the digest to be produced and emailed even when credentials are missing,
while still explicitly logging which legs are degraded.

Test: empty env produces JSON report + degraded leg labels, no SystemExit.
abiba-bot merged commit 5d70bbf25b into master 2026-09-21 11:26:33 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SyslogSolution/prose-contracts#126