From 31227ca44b2c8480ff9f1cfd8da2b00143fcd026 Mon Sep 17 00:00:00 2001 From: "prompt.ac/@jeffrey" Date: Thu, 8 Oct 2026 17:07:45 -0700 Subject: [PATCH] Remove exposed credentials and load native uploads from private host config --- .gitignore | 1 + false.work/unreal-builder/BUILD-AUTOMATION-GUIDE.md | 4 ++-- false.work/unreal-builder/docs/HORDE-AND-BUILDTOOLS.md | 2 +- false.work/unreal-builder/docs/MANUAL-BOOTSTRAP.md | 2 +- false.work/unreal-builder/docs/NEXT-STEPS.md | 4 ++-- false.work/unreal-builder/test-connection.ps1 | 6 ++---- fedac/native/scripts/upload-release.sh | 10 +++++----- fedac/native/upload.env | 6 ------ fedac/native/upload.env.example | 8 ++++++++ 9 files changed, 22 insertions(+), 21 deletions(-) delete mode 100644 fedac/native/upload.env create mode 100644 fedac/native/upload.env.example diff --git a/.gitignore b/.gitignore index bcc31cf48d..b2efc003c5 100644 --- a/.gitignore +++ b/.gitignore @@ -290,6 +290,7 @@ kidlisp-n64/peter-lemon-n64/ **/.tokens # Environment Files with Secrets +/fedac/native/upload.env .env.local .env.*.local .env.secret diff --git a/false.work/unreal-builder/BUILD-AUTOMATION-GUIDE.md b/false.work/unreal-builder/BUILD-AUTOMATION-GUIDE.md index 18e91397f4..e1b6fad3ab 100644 --- a/false.work/unreal-builder/BUILD-AUTOMATION-GUIDE.md +++ b/false.work/unreal-builder/BUILD-AUTOMATION-GUIDE.md @@ -99,7 +99,7 @@ p4 trust -y -f ssl:falsework.helixcore.io:1666 $env:P4PORT = "ssl:falsework.helixcore.io:1666" $env:P4USER = "machine" p4 login -# Enter password when prompted: AestheticComp1 +# Enter the machine account password from the private vault when prompted. # Create workspace p4 client spiderlily_build_workspace @@ -177,7 +177,7 @@ cd C:\scripts Add these secrets: - `P4_SERVER`: `ssl:falsework.helixcore.io:1666` - `P4_USER`: `machine` -- `P4_PASSWORD`: `AestheticComp1` (from vault) +- `P4_PASSWORD`: Read from the private vault - `P4_WORKSPACE`: `spiderlily_build_workspace` #### Trigger Builds diff --git a/false.work/unreal-builder/docs/HORDE-AND-BUILDTOOLS.md b/false.work/unreal-builder/docs/HORDE-AND-BUILDTOOLS.md index 6095049003..49ff9631ba 100644 --- a/false.work/unreal-builder/docs/HORDE-AND-BUILDTOOLS.md +++ b/false.work/unreal-builder/docs/HORDE-AND-BUILDTOOLS.md @@ -39,7 +39,7 @@ Invoke-WebRequest -Uri "https://cdist2.perforce.com/perforce/r24.1/bin.ntx64/p4. ```powershell p4 set P4PORT=ssl:falsework.helixcore.io:1666 p4 set P4USER=machine -p4 set P4PASSWD=AestheticComp1 +# Enter the machine account password from the private vault at the p4 login prompt. p4 login p4 sync ``` diff --git a/false.work/unreal-builder/docs/MANUAL-BOOTSTRAP.md b/false.work/unreal-builder/docs/MANUAL-BOOTSTRAP.md index 3e59d5f628..aabe80e84c 100644 --- a/false.work/unreal-builder/docs/MANUAL-BOOTSTRAP.md +++ b/false.work/unreal-builder/docs/MANUAL-BOOTSTRAP.md @@ -57,7 +57,7 @@ msiexec /i C:\EpicGamesLauncherInstaller.msi /quiet ```powershell p4 set P4PORT=ssl:falsework.helixcore.io:1666 p4 set P4USER=machine -p4 set P4PASSWD=AestheticComp1 +# Enter the machine account password from the private vault at the p4 login prompt. p4 set P4CLIENT=spiderlily_build_workspace p4 login p4 info # Test connection diff --git a/false.work/unreal-builder/docs/NEXT-STEPS.md b/false.work/unreal-builder/docs/NEXT-STEPS.md index c5e81a80c2..69c714a316 100644 --- a/false.work/unreal-builder/docs/NEXT-STEPS.md +++ b/false.work/unreal-builder/docs/NEXT-STEPS.md @@ -91,7 +91,7 @@ This will: ### Step 4: Configure Perforce Password (IN THE VM) ```powershell -p4 set P4PASSWD=AestheticComp1 +# Enter the machine account password from the private vault at the p4 login prompt. p4 login p4 info # Test connection @@ -145,7 +145,7 @@ Add these secrets: |-------------|-------| | `P4_SERVER` | `ssl:falsework.helixcore.io:1666` | | `P4_USER` | `machine` | -| `P4_PASSWORD` | `AestheticComp1` | +| `P4_PASSWORD` | Read from the private vault | | `P4_WORKSPACE` | `spiderlily_build_workspace` | | `P4_CLIENT_PATH` | `//depot/SpiderLily/SL_main/...` | | `PROJECT_NAME` | `SpiderLily` | diff --git a/false.work/unreal-builder/test-connection.ps1 b/false.work/unreal-builder/test-connection.ps1 index 7d4bd3a344..1bb2d439ce 100644 --- a/false.work/unreal-builder/test-connection.ps1 +++ b/false.work/unreal-builder/test-connection.ps1 @@ -9,8 +9,7 @@ $env:P4PORT = "ssl:falsework.helixcore.io:1666" $env:P4USER = "machine" $env:P4CLIENT = "spiderlily_build_workspace" -# Note: P4PASSWD should be set separately for security -# Run: p4 set P4PASSWD=AestheticComp1 +# Authenticate with p4 login; enter the machine account password from the private vault. Write-Host "Testing with:" -ForegroundColor Yellow Write-Host " Server: $env:P4PORT" @@ -52,8 +51,7 @@ if ($LASTEXITCODE -eq 0) { Write-Host " $loginStatus" -ForegroundColor Gray } else { Write-Host " ✗ Not logged in" -ForegroundColor Red - Write-Host " Please run: p4 set P4PASSWD=AestheticComp1" -ForegroundColor Yellow - Write-Host " Then run: p4 login" -ForegroundColor Yellow + Write-Host " Run p4 login and enter the machine account password from the private vault." -ForegroundColor Yellow exit 1 } diff --git a/fedac/native/scripts/upload-release.sh b/fedac/native/scripts/upload-release.sh index 4532ceddbb..16e51fbcb9 100755 --- a/fedac/native/scripts/upload-release.sh +++ b/fedac/native/scripts/upload-release.sh @@ -32,12 +32,12 @@ if [ -z "${DO_SPACES_KEY:-}" ] || [ -z "${DO_SPACES_SECRET:-}" ]; then [ -f "/tmp/.ac-upload-env" ] && { set -a; source "/tmp/.ac-upload-env"; set +a; } fi if [ -z "${DO_SPACES_KEY:-}" ] || [ -z "${DO_SPACES_SECRET:-}" ]; then - # Plaintext vault file, or in-repo fallback (oven ships upload.env in-tree). - # The oven's clone has no aesthetic-computer-vault/ sibling, so without - # this fallback the upload silently failed with "DO_SPACES_KEY not set". + # Private host configuration or vault file, never a tracked repository file. + # See upload.env.example. Host configuration also survives fresh checkouts. for candidate in \ - "${SCRIPT_DIR}/../../../aesthetic-computer-vault/fedac/native/upload.env" \ - "${SCRIPT_DIR}/../upload.env"; do + "${AC_NATIVE_UPLOAD_ENV:-${XDG_CONFIG_HOME:-$HOME/.config}/aesthetic-computer/native-upload.env}" \ + "/etc/aesthetic-computer/native-upload.env" \ + "${SCRIPT_DIR}/../../../aesthetic-computer-vault/fedac/native/upload.env"; do [ -f "$candidate" ] && { set -a; source "$candidate"; set +a; break; } done fi diff --git a/fedac/native/upload.env b/fedac/native/upload.env deleted file mode 100644 index d937b69ca7..0000000000 --- a/fedac/native/upload.env +++ /dev/null @@ -1,6 +0,0 @@ -# fedac/native OS release upload credentials -# DO Spaces: releases-aesthetic-computer (sfo3) -DO_SPACES_KEY=DO00HC2A29N6REC8LGFU -DO_SPACES_SECRET=+r0X/0++XKn2q71jepO3S1alrdSaXtc6L3tzDJTs4fA -DO_SPACES_ENDPOINT=https://sfo3.digitaloceanspaces.com -DO_SPACES_BUCKET=releases-aesthetic-computer diff --git a/fedac/native/upload.env.example b/fedac/native/upload.env.example new file mode 100644 index 0000000000..beb6aa2a88 --- /dev/null +++ b/fedac/native/upload.env.example @@ -0,0 +1,8 @@ +# Private OS release upload configuration. Provision from the vault into +# ~/.config/aesthetic-computer/native-upload.env (chmod 600), or on a build +# server into /etc/aesthetic-computer/native-upload.env with service access. +# AC_NATIVE_UPLOAD_ENV can select another private path. Never commit credentials. +DO_SPACES_KEY= +DO_SPACES_SECRET= +DO_SPACES_ENDPOINT=https://sfo3.digitaloceanspaces.com +DO_SPACES_BUCKET=releases-aesthetic-computer -- 2.51.2