27 lines
987 B
Python
27 lines
987 B
Python
"""Create deployment secrets locally, without printing or replacing existing secrets."""
|
|
|
|
import argparse
|
|
import base64
|
|
import os
|
|
import secrets
|
|
from pathlib import Path
|
|
|
|
parser = argparse.ArgumentParser()
|
|
parser.add_argument("--output", type=Path, default=Path(__file__).resolve().parent.parent / ".env")
|
|
args = parser.parse_args()
|
|
content = "\n".join([
|
|
"ADMIN_USERNAME=admin",
|
|
f"ADMIN_PASSWORD={secrets.token_urlsafe(24)}",
|
|
f"POSTGRES_PASSWORD={secrets.token_hex(24)}",
|
|
f"ENCRYPTION_KEY={base64.urlsafe_b64encode(secrets.token_bytes(32)).decode()}",
|
|
"WQ_EMAIL=", "WQ_PASSWORD=",
|
|
"LOCAL_PORT=8080", "DOMAIN=alpha.example.com", "",
|
|
])
|
|
try:
|
|
fd = os.open(args.output, os.O_CREAT | os.O_EXCL | os.O_WRONLY, 0o600)
|
|
except FileExistsError:
|
|
raise SystemExit(f"Already exists; left unchanged: {args.output}") from None
|
|
with os.fdopen(fd, "w") as output:
|
|
output.write(content)
|
|
print(f"Created {args.output}; read ADMIN_PASSWORD there for the initial login.")
|