26 lines
954 B
Python
26 lines
954 B
Python
|
|
"""Create deployment secrets locally, without printing or replacing existing secrets."""
|
||
|
|
|
||
|
|
import argparse
|
||
|
|
import base64
|
||
|
|
import os
|
||
|
|
import secrets
|
||
|
|
from pathlib import Path
|
||
|
|
|
||
|
|
parser = argparse.ArgumentParser()
|
||
|
|
parser.add_argument("--output", type=Path, default=Path(__file__).resolve().parent.parent / ".env")
|
||
|
|
args = parser.parse_args()
|
||
|
|
content = "\n".join([
|
||
|
|
"ADMIN_USERNAME=admin",
|
||
|
|
f"ADMIN_PASSWORD={secrets.token_urlsafe(24)}",
|
||
|
|
f"POSTGRES_PASSWORD={secrets.token_hex(24)}",
|
||
|
|
f"ENCRYPTION_KEY={base64.urlsafe_b64encode(secrets.token_bytes(32)).decode()}",
|
||
|
|
"LOCAL_PORT=8080", "DOMAIN=alpha.example.com", "",
|
||
|
|
])
|
||
|
|
try:
|
||
|
|
fd = os.open(args.output, os.O_CREAT | os.O_EXCL | os.O_WRONLY, 0o600)
|
||
|
|
except FileExistsError:
|
||
|
|
raise SystemExit(f"Already exists; left unchanged: {args.output}") from None
|
||
|
|
with os.fdopen(fd, "w") as output:
|
||
|
|
output.write(content)
|
||
|
|
print(f"Created {args.output}; read ADMIN_PASSWORD there for the initial login.")
|