hardening: strengthen deploy and validation gates
This commit is contained in:
@@ -33,6 +33,10 @@ AW_LOG_TO_FILE=true
|
||||
# Health Check Configuration
|
||||
AW_HEALTH_CHECK_ENABLED=true
|
||||
AW_HEALTH_CHECK_INTERVAL=60
|
||||
AW_EXPECT_START_OF_DAY=00:00
|
||||
AW_EXPECT_ALWAYS_ACTIVE_PATTERN=aw-watcher-window
|
||||
AW_EXPECT_LANDINGPAGE=/activity/SHARKON2025/view/
|
||||
AW_HEALTH_STRICT_FILEOPS=0
|
||||
|
||||
# Integration Test Configuration
|
||||
AW_INTEGRATION_TEST_ENABLED=false
|
||||
|
||||
@@ -8,6 +8,11 @@ SERVICES=("activitywatch-server" "aw-worktime-api" "aw-worktime-ui-bridge")
|
||||
UNHEALTHY_SERVICES=()
|
||||
WARNINGS=()
|
||||
|
||||
if [[ -f /etc/activitywatch/aw-server.env ]]; then
|
||||
# shellcheck disable=SC1091
|
||||
source /etc/activitywatch/aw-server.env
|
||||
fi
|
||||
|
||||
check_service() {
|
||||
local service=$1
|
||||
if [[ "$service" == "aw-worktime-ui-bridge" ]]; then
|
||||
@@ -39,6 +44,38 @@ check_api_endpoint() {
|
||||
fi
|
||||
}
|
||||
|
||||
read_setting_value() {
|
||||
local key=$1
|
||||
curl -fsS --max-time 10 "http://127.0.0.1:5600/api/0/settings/${key}" 2>/dev/null | \
|
||||
python3 -c 'import json,sys; print(json.load(sys.stdin))'
|
||||
}
|
||||
|
||||
check_expected_setting() {
|
||||
local key=$1
|
||||
local expected=$2
|
||||
local label=${3:-$1}
|
||||
|
||||
if [[ -z "$expected" ]]; then
|
||||
echo "⚠ expected value for ${label} is not configured, skipping drift check"
|
||||
WARNINGS+=("${key}-expected-missing")
|
||||
return
|
||||
fi
|
||||
|
||||
local actual
|
||||
if ! actual="$(read_setting_value "$key" 2>/dev/null)"; then
|
||||
echo "✗ failed to read setting ${label}"
|
||||
UNHEALTHY_SERVICES+=("setting-${key}")
|
||||
return
|
||||
fi
|
||||
|
||||
if [[ "$actual" == "$expected" ]]; then
|
||||
echo "✓ ${label} matches expected value (${expected})"
|
||||
else
|
||||
echo "✗ ${label} drift detected: actual='${actual}' expected='${expected}'"
|
||||
UNHEALTHY_SERVICES+=("setting-${key}")
|
||||
fi
|
||||
}
|
||||
|
||||
check_dlp_transport_freshness() {
|
||||
local dlp_health="${DLP_HEALTH_BIN:-/usr/local/bin/dlp-health-check}"
|
||||
local result
|
||||
@@ -92,6 +129,9 @@ echo
|
||||
check_api_endpoint "http://127.0.0.1:5600/api/0/info" "activitywatch-server"
|
||||
check_api_endpoint "http://127.0.0.1:5610/reports/worktime/today" "aw-worktime-api"
|
||||
check_dlp_transport_freshness "http://127.0.0.1:5600/api/0" "900" "${AW_HEALTH_STRICT_FILEOPS:-0}"
|
||||
check_expected_setting "startOfDay" "${AW_EXPECT_START_OF_DAY:-}" "startOfDay"
|
||||
check_expected_setting "always_active_pattern" "${AW_EXPECT_ALWAYS_ACTIVE_PATTERN:-}" "always_active_pattern"
|
||||
check_expected_setting "landingpage" "${AW_EXPECT_LANDINGPAGE:-}" "landingpage"
|
||||
|
||||
echo
|
||||
|
||||
|
||||
Reference in New Issue
Block a user