security: remove hardcoded credentials, untrack .env

- config/system_config.py: defaults are localhost with empty credentials;
  real hosts/secrets must come from env (.env or docker-compose)
- main.py: help text lists env var names instead of real NATS host/user
- doormile_test.py: reads infra config from env instead of literals
- untrack .env, ignore .env/.env.*, add .env.example with keys only
- pytest.ini: testpaths=tests so doormile_test.py isn't collected

Credentials remain in git history and must be rotated.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012AJLYcbTHCe45fyFnMfEin
This commit is contained in:
2026-09-22 15:52:06 +05:30
parent 7227d2d2bd
commit be8103c1d2
6 changed files with 57 additions and 27 deletions

View File

@@ -1,27 +1,28 @@
"""System configuration for LogiFlow AI."""
import os
# Infrastructure Connections — values come from environment / .env file.
# Hardcoded strings are last-resort defaults; set the matching env var in production.
NATS_URL = os.getenv("NATS_URL", "nats://doormile:Package@321#@66.116.226.161:4223")
NATS_HOST = os.getenv("NATS_HOST", "66.116.226.161")
NATS_PORT = int(os.getenv("NATS_PORT", "4223"))
NATS_USER = os.getenv("NATS_USER", "doormile")
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "Package@321#")
# Infrastructure Connections — values come from environment / .env file
# (see .env.example). Defaults point at localhost with no credentials so the
# system runs in local-fallback mode; real hosts and secrets are never in code.
NATS_URL = os.getenv("NATS_URL", "nats://localhost:4222")
NATS_HOST = os.getenv("NATS_HOST", "localhost")
NATS_PORT = int(os.getenv("NATS_PORT", "4222"))
NATS_USER = os.getenv("NATS_USER", "")
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "")
REDIS_HOST = os.getenv("REDIS_HOST", "66.116.226.255")
REDIS_PORT = int(os.getenv("REDIS_PORT", "6380"))
REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "Package@321#")
REDIS_HOST = os.getenv("REDIS_HOST", "localhost")
REDIS_PORT = int(os.getenv("REDIS_PORT", "6379"))
REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "")
# Postgres — individual params to avoid @ in password breaking DSN parsing
DB_HOST = os.getenv("DB_HOST", "31.97.228.132")
DB_PORT = int(os.getenv("DB_PORT", "5433"))
DB_HOST = os.getenv("DB_HOST", "localhost")
DB_PORT = int(os.getenv("DB_PORT", "5432"))
DB_NAME = os.getenv("DB_NAME", "logistics")
DB_USER = os.getenv("DB_USER", "admin")
DB_PASSWORD = os.getenv("DB_PASSWORD", "Package@321#")
DB_USER = os.getenv("DB_USER", "postgres")
DB_PASSWORD = os.getenv("DB_PASSWORD", "")
GO_API_BASE_URL = os.getenv("GO_API_BASE_URL", "http://localhost:8080")
INTERNAL_API_KEY = os.getenv("INTERNAL_API_KEY", "doormile-internal-2024")
INTERNAL_API_KEY = os.getenv("INTERNAL_API_KEY", "")
# Route Optimization API (Valhalla-backed road routing). The ExpressDispatchAgent
# calls its Doormile endpoint (/api/v1/optimization/doormile/sequence) to order a