From 59ed7cdbf746b583b24e2efe587622d8938f5d70 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 21 Sep 2026 11:30:42 +0000 Subject: [PATCH] fix(daily-infra-report): remove vestigial ZULIP_API_KEY requirement, exit non-zero on failed send 1. Remove vestigial ZULIP_API_KEY requirement: - /api/v1/server_settings is a PUBLIC endpoint (verified HTTP 200 with or without credential) - No Zulip API key is required for this call - If a future leg genuinely needs abiba-bot's key, it must prove it with a 200 from /api/v1/users/me as abiba-bot and label itself degraded when it cannot - Never fall back to the vault's shared ZULIP_API_KEY 2. Make failed sends exit non-zero: - A degraded leg (no credential configured) must stay exit 0 - A failed send (attempted and failed) must exit 1 - This distinguishes 'not configured' from 'attempted and failed' Test evidence: - No-credential run: exit 0, digest still produced - Wrong password: exit 1, labelled SMTP error - grep -n ZULIP_API_KEY: only comment reference remains --- scripts/daily-infra-report.py | 18 ++++++++++-------- 1 file changed, 10 insertions(+), 8 deletions(-) diff --git a/scripts/daily-infra-report.py b/scripts/daily-infra-report.py index 27e4867..4045ea9 100755 --- a/scripts/daily-infra-report.py +++ b/scripts/daily-infra-report.py @@ -22,14 +22,12 @@ AUTH = "Authorization: PVEAPIToken=«vault: infrastructure/production PVE_API_TO ZULIP_SITE = "https://chat.sysloggh.net" ZULIP_EMAIL = "abiba-bot@chat.sysloggh.net" -ZULIP_API_KEY = os.environ.get("ZULIP_API_KEY", "") -if not ZULIP_API_KEY: - ZULIP_AUTH = None - DEGRADED_LEGS = ["credential-missing: ZULIP_API_KEY"] - print(" ⚠️ Degraded leg: credential-missing: ZULIP_API_KEY", file=sys.stderr) -else: - ZULIP_AUTH = f"{ZULIP_EMAIL}:{ZULIP_API_KEY}" - DEGRADED_LEGS = [] +# Note: /api/v1/server_settings is a PUBLIC endpoint (verified HTTP 200 with or without credential). +# No Zulip API key is required for this call. If a future leg genuinely needs abiba-bot's key, +# it must prove it with a 200 from /api/v1/users/me as abiba-bot and label itself degraded when it cannot. +# Never fall back to the vault's shared ZULIP_API_KEY. +ZULIP_AUTH = None +DEGRADED_LEGS = [] LITELLM_PUBLIC = "https://litellm.sysloggh.net" LITELLM_BACKEND = "192.168.68.116" @@ -725,6 +723,10 @@ if __name__ == "__main__": else: print("\n✅ All legs fully credentialed") + # A failed send must exit non-zero; a degraded leg (no credential) must stay exit 0 + if not ok: + sys.exit(1) + issues = sum(1 for i in ["red"] if report.get("zulip_ext", {}).get("connected") == False) print(f"\n📋 Summary:") print(f" Proxmox: {report['nodes_online']}/{report['node_count']} nodes online") -- 2.54.0