From 0b0a9e47a66f0d42cb0dd828223e20be19275c16 Mon Sep 17 00:00:00 2001 From: Mike Langmayr <1809691+mikelangmayr@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:57:51 -0700 Subject: [PATCH] Name the shared broker in HispecDaemon and apply LIBBY_ environment overrides --- docs/operations/systemd.md | 12 ++++++++++++ src/hispec/daemon.py | 14 ++++++++++++++ 2 files changed, 26 insertions(+) diff --git a/docs/operations/systemd.md b/docs/operations/systemd.md index 90f2fae..e78592b 100644 --- a/docs/operations/systemd.md +++ b/docs/operations/systemd.md @@ -211,6 +211,18 @@ the value never reaches git. For the PDU that is `hardware.username_env` and variables. Inline `hardware.username` / `hardware.password` still work for a bench test, but the daemon logs a warning against committing them. +Any top-level config key can also be replaced by a `LIBBY_` variable, +which suits a value that is itself a secret. `HispecDaemon` names the broker +but holds no password, so every host supplies one: + +```bash +sudo tee -a /etc/hispec/secrets.env <<'EOF' +LIBBY_RABBITMQ_URL=amqp://:@131.215.200.214 +EOF +``` + +Without it a daemon is refused with `ACCESS_REFUSED ... mechanism PLAIN`. + ## Troubleshooting Start here: diff --git a/src/hispec/daemon.py b/src/hispec/daemon.py index c0a003b..f4747e4 100644 --- a/src/hispec/daemon.py +++ b/src/hispec/daemon.py @@ -1,5 +1,12 @@ +"""Common base for the HISPEC daemons: transport, broker and config sources.""" + +from typing import Optional + from libby.daemon import LibbyDaemon +# The shared broker, on hispec-new; credentials come from LIBBY_RABBITMQ_URL +BROKER_URL = "amqp://131.215.200.214" + class HispecDaemon(LibbyDaemon): """Instantiates the HispecDaemon base using LibbyDaemon. @@ -8,3 +15,10 @@ class HispecDaemon(LibbyDaemon): transport = "rabbitmq" discovery_enabled = False + rabbitmq_url = BROKER_URL + + @classmethod + def from_config_file(cls, path: str, daemon_id: Optional[str] = None, *, + env_prefix: Optional[str] = "LIBBY_") -> "HispecDaemon": + """Build a daemon, applying LIBBY_* environment overrides by default.""" + return super().from_config_file(path, daemon_id, env_prefix=env_prefix)