Commit Graph

2 Commits

Author SHA1 Message Date
aa3bb35733 fix(deploy): pass NATS_HOST/NATS_PORT and autonomy gates through compose
The agents connect with NATS_HOST/NATS_PORT (NATS_URL is informational), but
docker-compose only forwarded NATS_URL. That was masked while system_config
carried the real host as a hardcoded default; after the secrets scrub the
default is localhost, so a deploy would have sent every NATS connection —
message bus, DispatchAgent, ExceptionAgent — to localhost.

Also forwards the autonomy gates (all default false) plus DISPATCH_REALERT_EVERY
and LLM_MODEL, so production behaviour is set in .env rather than by code
defaults. .env.example updated to match.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012AJLYcbTHCe45fyFnMfEin
2026-09-22 16:43:51 +05:30
be8103c1d2 security: remove hardcoded credentials, untrack .env
- config/system_config.py: defaults are localhost with empty credentials;
  real hosts/secrets must come from env (.env or docker-compose)
- main.py: help text lists env var names instead of real NATS host/user
- doormile_test.py: reads infra config from env instead of literals
- untrack .env, ignore .env/.env.*, add .env.example with keys only
- pytest.ini: testpaths=tests so doormile_test.py isn't collected

Credentials remain in git history and must be rotated.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012AJLYcbTHCe45fyFnMfEin
2026-09-22 15:52:06 +05:30