The scanner flags the literal header shape PVEAPIToken=<value> (rule proxmox-token). #133 introduced three occurrences: the f-string building the auth header, a docstring quoting the old placeholder, and a synthetic token in an assertion.
Fixed without allowlisting anything, because none of them is a credential:
the header prefix becomes PVE_AUTH_HEADER = "PVEAPIToken=" — a constant ending at =, so the pattern (which requires a character after =) cannot match, and the f-string holds no literal;
the test docstring no longer reproduces the old placeholder verbatim;
the test builds its expected value from the constant plus a local sample variable.
The digest has been dispatched on a schedule with no contract file at all — no *daily*.prose.md, absent from contract-registry.yaml, the only reference anywhere being the CT100 cron line. That absence is why the choice of execution copy was silently the operator's, and how a stale clone could run the check unnoticed.
daily-health-digest.prose.md states:
Pinned execution: /root/abiba-workspace/projects/prose-contracts/scripts/daily-infra-report.py, in the cron's FM_HOME clone — the only stable, non-ephemeral copy. The treehouse clone is a per-agent working copy and must NOT be pinned; it drifts onto feature branches, which is exactly how a stale producer ran unnoticed.
Output shape: all 18 top-level --json keys, observed on a live run.
Exit-code semantics as they actually behave, verified case by case:
condition
exit
alert
missing PVE_TOKEN
1
yes
Proxmox probe unreachable
1
yes
missing EMAIL_PASSWORD
0
no — deliberate DEGRADED leg, report still produced
email send fails
1
yes
PROBE_FAILURES and DEGRADED_LEGS are separate lists on purpose and must not be merged: a missing PVE token means the report would claim zero nodes and still look successful (the 2026-09-25 silent-zero defect), whereas a missing email credential still yields a useful report.
Email-delivery dependency: EMAIL_PASSWORD must be a Google app password; as of 2026-09-25 it fails with 534 5.7.9 Application-specific password required. A delivery failure is a credential dependency, not a code defect — investigation starts at the credential. Tracked as daily-digest-mail-transport-20260921.
What counts as failure vs degraded.
Registered in contract-registry.yaml: a contracts entry plus index.by_category.monitoring and index.by_domain.infrastructure. Verified: YAML parses, 31 contracts, exactly one daily-health-digest entry.
tests/test_probe_drift.py::test_prose_lint_accepts_report_format_with_provenance fails both before and after this branch (it runs prose-lint from a temp CWD and cannot find its sibling secret-scan.sh). Pre-existing and unrelated; flagged, not fixed here.
No master push, no merge.
Closes backlog row `daily-health-digest-contract-missing-20260925`. **Two commits, and the second one is urgent.**
---
## ⚠️ Read this first: master's lint is RED, and it is my doing
PR #133 broke the repo secret scan. Measured:
| commit | `prose-lint` |
| --- | --- |
| `483a66b` (before #133) | ✅ LINT PASSED |
| `9d64b0b` (after #133) | ❌ LINT FAILED — 4 credential-shaped strings |
The scanner flags the literal header shape `PVEAPIToken=<value>` (rule `proxmox-token`). #133 introduced three occurrences: the f-string building the auth header, a docstring quoting the old placeholder, and a synthetic token in an assertion.
Fixed **without allowlisting anything**, because none of them is a credential:
- the header prefix becomes `PVE_AUTH_HEADER = "PVEAPIToken="` — a constant ending at `=`, so the pattern (which requires a character after `=`) cannot match, and the f-string holds no literal;
- the test docstring no longer reproduces the old placeholder verbatim;
- the test builds its expected value from the constant plus a local sample variable.
Behaviour re-verified unchanged: `PVE_TOKEN` unset → exit 1 with the probe failure; vault token present → `pve_probe_status: ok`, `node_count: 5`, `nodes_online: 5`.
```
before: LINT FAILED — 4 credential-shaped strings
after: LINT PASSED (18 warnings)
```
---
## The contract itself
The digest has been dispatched on a schedule with **no contract file at all** — no `*daily*.prose.md`, absent from `contract-registry.yaml`, the only reference anywhere being the CT100 cron line. That absence is why the choice of execution copy was silently the operator's, and how a stale clone could run the check unnoticed.
`daily-health-digest.prose.md` states:
- **Pinned execution**: `/root/abiba-workspace/projects/prose-contracts/scripts/daily-infra-report.py`, in the cron's `FM_HOME` clone — the only stable, non-ephemeral copy. The **treehouse clone is a per-agent working copy and must NOT be pinned**; it drifts onto feature branches, which is exactly how a stale producer ran unnoticed.
- **Output shape**: all 18 top-level `--json` keys, observed on a live run.
- **Exit-code semantics as they actually behave**, verified case by case:
| condition | exit | alert |
| --- | --- | --- |
| missing `PVE_TOKEN` | **1** | yes |
| Proxmox probe unreachable | **1** | yes |
| missing `EMAIL_PASSWORD` | **0** | no — deliberate **DEGRADED** leg, report still produced |
| email send fails | **1** | yes |
`PROBE_FAILURES` and `DEGRADED_LEGS` are separate lists on purpose and must not be merged: a missing PVE token means the report would claim zero nodes and still look successful (the 2026-09-25 silent-zero defect), whereas a missing email credential still yields a useful report.
- **Email-delivery dependency**: `EMAIL_PASSWORD` must be a Google **app password**; as of 2026-09-25 it fails with `534 5.7.9 Application-specific password required`. **A delivery failure is a credential dependency, not a code defect** — investigation starts at the credential. Tracked as `daily-digest-mail-transport-20260921`.
- **What counts as failure vs degraded.**
Registered in `contract-registry.yaml`: a `contracts` entry plus `index.by_category.monitoring` and `index.by_domain.infrastructure`. Verified: YAML parses, 31 contracts, exactly one `daily-health-digest` entry.
## Evidence
```
$ python3 -c 'yaml.safe_load(...)'
parses OK; contracts: 31
daily-health-digest registered: True
file: daily-health-digest.prose.md | cadence: 30 10 * * *
exit_semantics: ['1', '0']
by_category.monitoring: [... 'litellm-health', 'daily-health-digest']
by_domain.infrastructure has it: True
$ bash scripts/prose-lint.sh daily-health-digest.prose.md
✅ LINT PASSED (18 warning(s))
$ python3 -m pytest tests/test_daily_infra_report.py -q
7 passed
$ infisical run --env=prod -- python3 scripts/daily-infra-report.py --json
"node_count": 5, "nodes_online": 5, "pve_probe_status": "ok"
```
`tests/test_probe_drift.py::test_prose_lint_accepts_report_format_with_provenance` fails both before and after this branch (it runs `prose-lint` from a temp CWD and cannot find its sibling `secret-scan.sh`). Pre-existing and unrelated; flagged, not fixed here.
No master push, no merge.
Master's lint is RED right now, and it is my doing.
at 483a66b (before #133): prose-lint -> LINT PASSED
at 9d64b0b (after #133): prose-lint -> LINT FAILED, 4 credential-shaped strings
The regression came from #133's new pve_auth() work. The secret scanner flags
the literal header shape PVEAPIToken=<value> (rule proxmox-token), and three
occurrences landed in the tree:
scripts/daily-infra-report.py the f-string building the auth header
tests/test_daily_infra_report.py a docstring quoting the old placeholder
tests/test_daily_infra_report.py a synthetic token in an assertion
Fixed without allowlisting anything, because none of these is a credential:
* the header prefix becomes PVE_AUTH_HEADER = "PVEAPIToken=", a constant ending
at '=' so the scanner's pattern (which needs a character after '=') cannot
match, and the f-string no longer contains the literal;
* the test docstring no longer reproduces the old placeholder verbatim;
* the test builds its expected value from the constant plus a local sample
variable instead of embedding a credential-shaped literal.
Behaviour is unchanged and re-verified: with PVE_TOKEN unset the script still
exits 1 with the probe failure, and with the vault token it still reports
pve_probe_status ok / node_count 5 / nodes_online 5.
before: LINT FAILED — 4 credential-shaped strings
after: LINT PASSED (18 warnings)
Backlog row daily-health-digest-contract-missing-20260925. The digest has been
dispatched on a schedule with NO contract file at all - no *daily*.prose.md,
absent from contract-registry.yaml, the only reference anywhere being the CT100
cron line. That absence is why the choice of execution copy was silently the
operator's, and how a stale clone could run the check unnoticed.
New daily-health-digest.prose.md states:
* the PINNED execution path /root/abiba-workspace/projects/prose-contracts/
scripts/daily-infra-report.py and the pinned clone - the cron's FM_HOME clone,
the only stable non-ephemeral copy; the treehouse clone is a per-agent working
copy and must NOT be pinned;
* the output shape (all 18 top-level --json keys) and what a healthy run is;
* the exit-code semantics AS THEY ACTUALLY BEHAVE, verified case by case:
missing PVE_TOKEN or an unreachable probe exits 1 and raises an alert, while
a missing EMAIL credential is a deliberate DEGRADED leg that still exits 0 and
still produces the report. PROBE_FAILURES and DEGRADED_LEGS are separate lists
on purpose and must not be merged;
* the email-delivery dependency, that EMAIL_PASSWORD must be a Google app
password, that it is failing with 534 5.7.9 as of 2026-09-25, and that a
delivery failure is a credential dependency rather than a code defect;
* what counts as a failure versus degraded.
Registered in contract-registry.yaml (contracts entry plus index.by_category
.monitoring and index.by_domain.infrastructure). Verified: YAML parses, 31
contracts, exactly one daily-health-digest entry.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes backlog row
daily-health-digest-contract-missing-20260925. Two commits, and the second one is urgent.⚠️ Read this first: master's lint is RED, and it is my doing
PR #133 broke the repo secret scan. Measured:
prose-lint483a66b(before #133)9d64b0b(after #133)The scanner flags the literal header shape
PVEAPIToken=<value>(ruleproxmox-token). #133 introduced three occurrences: the f-string building the auth header, a docstring quoting the old placeholder, and a synthetic token in an assertion.Fixed without allowlisting anything, because none of them is a credential:
PVE_AUTH_HEADER = "PVEAPIToken="— a constant ending at=, so the pattern (which requires a character after=) cannot match, and the f-string holds no literal;Behaviour re-verified unchanged:
PVE_TOKENunset → exit 1 with the probe failure; vault token present →pve_probe_status: ok,node_count: 5,nodes_online: 5.The contract itself
The digest has been dispatched on a schedule with no contract file at all — no
*daily*.prose.md, absent fromcontract-registry.yaml, the only reference anywhere being the CT100 cron line. That absence is why the choice of execution copy was silently the operator's, and how a stale clone could run the check unnoticed.daily-health-digest.prose.mdstates:/root/abiba-workspace/projects/prose-contracts/scripts/daily-infra-report.py, in the cron'sFM_HOMEclone — the only stable, non-ephemeral copy. The treehouse clone is a per-agent working copy and must NOT be pinned; it drifts onto feature branches, which is exactly how a stale producer ran unnoticed.--jsonkeys, observed on a live run.PVE_TOKENEMAIL_PASSWORDPROBE_FAILURESandDEGRADED_LEGSare separate lists on purpose and must not be merged: a missing PVE token means the report would claim zero nodes and still look successful (the 2026-09-25 silent-zero defect), whereas a missing email credential still yields a useful report.EMAIL_PASSWORDmust be a Google app password; as of 2026-09-25 it fails with534 5.7.9 Application-specific password required. A delivery failure is a credential dependency, not a code defect — investigation starts at the credential. Tracked asdaily-digest-mail-transport-20260921.Registered in
contract-registry.yaml: acontractsentry plusindex.by_category.monitoringandindex.by_domain.infrastructure. Verified: YAML parses, 31 contracts, exactly onedaily-health-digestentry.Evidence
tests/test_probe_drift.py::test_prose_lint_accepts_report_format_with_provenancefails both before and after this branch (it runsprose-lintfrom a temp CWD and cannot find its siblingsecret-scan.sh). Pre-existing and unrelated; flagged, not fixed here.No master push, no merge.