"""Create deployment secrets locally, without printing or replacing existing secrets.""" import argparse import base64 import os import secrets from pathlib import Path parser = argparse.ArgumentParser() parser.add_argument("--output", type=Path, default=Path(__file__).resolve().parent.parent / ".env") args = parser.parse_args() content = "\n".join([ "ADMIN_USERNAME=admin", f"ADMIN_PASSWORD={secrets.token_urlsafe(24)}", f"POSTGRES_PASSWORD={secrets.token_hex(24)}", f"ENCRYPTION_KEY={base64.urlsafe_b64encode(secrets.token_bytes(32)).decode()}", "LOCAL_PORT=8080", "DOMAIN=alpha.example.com", "", ]) try: fd = os.open(args.output, os.O_CREAT | os.O_EXCL | os.O_WRONLY, 0o600) except FileExistsError: raise SystemExit(f"Already exists; left unchanged: {args.output}") from None with os.fdopen(fd, "w") as output: output.write(content) print(f"Created {args.output}; read ADMIN_PASSWORD there for the initial login.")