Files
ss-tools/scripts/full-flow-finance-env.py
busya bcc69f4bbe feat(dashboard-testing): add sampled traversal and ClickHouse test lab
Add versioned metric graph authority, owned browser evidence, paginated and all-tab traversal, deterministic sampling policies, and analyst-facing run inspection.

Provision the DEV/PREPROD/PROD Superset, Gitea and million-row ClickHouse lab; retain reproducible lifecycle evidence and explicit incomplete-traversal limits.
2026-10-02 10:54:42 +03:00

59 lines
2.5 KiB
Python

#!/usr/bin/env python3
# #region FullFlow.FinanceMillion.Environment [C:4] [TYPE Module] [SEMANTICS credentials,private,additive,fixture]
# @PRE An existing owner-controlled mode0600 full-flow env is supplied; no production env is used.
# @POST Adds one strong ClickHouse secret once, preserving every existing byte/key and printing only the path.
# @INVARIANT Existing secrets are never replaced; symlinks/insecure permissions/empty existing credentials refuse.
import fcntl
import os
from pathlib import Path
import secrets
import stat
import sys
# #region FullFlow.FinanceMillion.Environment.Validate [C:3] [TYPE Function] [SEMANTICS permission,ownership,regular-file]
def validate_private_file(descriptor):
info = os.fstat(descriptor)
if not stat.S_ISREG(info.st_mode) or info.st_uid != os.getuid():
raise ValueError('PRIVATE_LAB_ENV_REQUIRED')
if stat.S_IMODE(info.st_mode) != 0o600:
raise ValueError('PRIVATE_LAB_ENV_MODE_0600_REQUIRED')
# #endregion FullFlow.FinanceMillion.Environment.Validate
# #region FullFlow.FinanceMillion.Environment.Extend [C:4] [TYPE Function] [SEMANTICS secret,append,idempotent]
# @SIDE_EFFECT Locks the private file and appends only the missing generated lab credential; no secret is logged.
# @RELATION CALLS -> [FullFlow.FinanceMillion.Environment.Validate]
def extend(path):
descriptor = os.open(path, os.O_RDWR | os.O_NOFOLLOW)
with os.fdopen(descriptor, 'r+') as target:
fcntl.flock(target, fcntl.LOCK_EX)
validate_private_file(target.fileno())
content = target.read()
entries = [line for line in content.splitlines() if line.startswith('CLICKHOUSE_PASSWORD=')]
if entries:
if len(entries) != 1 or not entries[0].split('=', 1)[1].strip():
raise ValueError('CLICKHOUSE_SECRET_INVALID')
return
target.seek(0, os.SEEK_END)
separator = '' if not content or content.endswith('\n') else '\n'
target.write(f'{separator}CLICKHOUSE_PASSWORD={secrets.token_hex(24)}\n')
target.flush()
os.fsync(target.fileno())
# #endregion FullFlow.FinanceMillion.Environment.Extend
# #region FullFlow.FinanceMillion.Environment.Main [C:2] [TYPE Function] [SEMANTICS cli,private-path]
def main():
if len(sys.argv) != 2:
raise SystemExit('Usage: full-flow-finance-env.py <existing-private-full-flow-env>')
path = Path(sys.argv[1])
extend(path)
print(path)
# #endregion FullFlow.FinanceMillion.Environment.Main
if __name__ == '__main__':
main()
# #endregion FullFlow.FinanceMillion.Environment