Mask the dburi password in queue init/migrate output
This commit is contained in:
parent
a3cc13230f
commit
5cc32f111e
3 changed files with 22 additions and 2 deletions
|
|
@ -1,11 +1,14 @@
|
||||||
# Changelog
|
# Changelog
|
||||||
## [Unreleased]
|
## [Unreleased]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- `ingester.queue.dburi`: a SQLAlchemy async URL (e.g. `postgresql+asyncpg://user:pw@host/db`) points the ingester queue at a database server. SQLite remains the default when unset. The Postgres path claims jobs with `FOR UPDATE SKIP LOCKED`, so multiple ingester processes can share one queue.
|
||||||
|
|
||||||
## [0.53.0] - 2026-06-03
|
## [0.53.0] - 2026-06-03
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `ingester.queue.dburi`: a SQLAlchemy async URL (e.g. `postgresql+asyncpg://user:pw@host/db`) points the ingester queue at a database server. SQLite remains the default when unset. The Postgres path claims jobs with `FOR UPDATE SKIP LOCKED`, so multiple ingester processes can share one queue.
|
|
||||||
- `ingester.queue.retention_days` (default 30): the reaper deletes succeeded/dead jobs whose `completed_at` is older than the window. `null` disables pruning.
|
- `ingester.queue.retention_days` (default 30): the reaper deletes succeeded/dead jobs whose `completed_at` is older than the window. `null` disables pruning.
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
|
||||||
|
|
@ -4,6 +4,7 @@ from pathlib import Path
|
||||||
|
|
||||||
import typer
|
import typer
|
||||||
from dotenv import find_dotenv, load_dotenv
|
from dotenv import find_dotenv, load_dotenv
|
||||||
|
from sqlalchemy import make_url
|
||||||
|
|
||||||
load_dotenv(find_dotenv(usecwd=True))
|
load_dotenv(find_dotenv(usecwd=True))
|
||||||
|
|
||||||
|
|
@ -90,7 +91,11 @@ def _resolve_queue_config(config: AppConfig, override: Path | None) -> QueueConf
|
||||||
|
|
||||||
|
|
||||||
def _queue_target(queue: QueueConfig) -> str:
|
def _queue_target(queue: QueueConfig) -> str:
|
||||||
return queue.dburi or str(queue.path)
|
"""A display string for the queue location, with any dburi password
|
||||||
|
masked so it isn't echoed to the terminal or logs."""
|
||||||
|
if queue.dburi:
|
||||||
|
return make_url(queue.dburi).render_as_string(hide_password=True)
|
||||||
|
return str(queue.path)
|
||||||
|
|
||||||
|
|
||||||
async def _ensure_schema(queue: QueueConfig) -> None:
|
async def _ensure_schema(queue: QueueConfig) -> None:
|
||||||
|
|
|
||||||
|
|
@ -111,6 +111,18 @@ def test_queue_migrate(tmp_path, monkeypatch):
|
||||||
assert "up to date" in result.output
|
assert "up to date" in result.output
|
||||||
|
|
||||||
|
|
||||||
|
def test_queue_target_masks_dburi_password():
|
||||||
|
from haiku.rag.config import QueueConfig
|
||||||
|
from haiku.rag.ingester.cli import _queue_target
|
||||||
|
|
||||||
|
target = _queue_target(
|
||||||
|
QueueConfig(dburi="postgresql+asyncpg://user:secret@host:5432/db")
|
||||||
|
)
|
||||||
|
assert "secret" not in target
|
||||||
|
assert "***" in target
|
||||||
|
assert "user" in target and "host:5432/db" in target
|
||||||
|
|
||||||
|
|
||||||
# --- config loading ---
|
# --- config loading ---
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue