security: remove hardcoded credentials, untrack .env

- config/system_config.py: defaults are localhost with empty credentials;
  real hosts/secrets must come from env (.env or docker-compose)
- main.py: help text lists env var names instead of real NATS host/user
- doormile_test.py: reads infra config from env instead of literals
- untrack .env, ignore .env/.env.*, add .env.example with keys only
- pytest.ini: testpaths=tests so doormile_test.py isn't collected

Credentials remain in git history and must be rotated.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012AJLYcbTHCe45fyFnMfEin
This commit is contained in:
2026-09-22 15:52:06 +05:30
parent 7227d2d2bd
commit be8103c1d2
6 changed files with 57 additions and 27 deletions

16
.env.example Normal file
View File

@@ -0,0 +1,16 @@
GO_API_BASE_URL=
NATS_URL=
REDIS_HOST=
REDIS_PORT=
REDIS_PASSWORD=
INTERNAL_API_KEY=
DB_HOST=
DB_PORT=
DB_NAME=
DB_USER=
DB_PASSWORD=
NATS_USER=
NATS_PASSWORD=
ANTHROPIC_API_KEY=
LLM_MODEL=claude-opus-4-8
LOG_LEVEL=INFO