#!/usr/bin/env bash # Provision a project root for the dedicated Jazz storage-server topology. # # Generates 256-bit backend/admin secrets, writes a 0600 env file for the # storage server and a separate 0600 env file for client services, and prints # credential-dark next steps. Secrets are never echoed, logged, or written to # world-readable files. Idempotent: an existing env file is left untouched # unless FORCE=1. # # Usage: # scripts/provision-jazz-storage.sh /path/to/project [--force] # # Outputs (under /.thoughtstream/): # state/jazz.sqlite.server.env — for scripts/serve-jazz-storage.ts (owner) # jazz-clients.env — for client services (JAZZ_SERVER_URL, # JAZZ_BACKEND_SECRET, storage mode=client) # # The client env file deliberately does NOT contain the admin secret. # Deployment notes: # - The storage server and the trusted runtime may share an isolated # host/container boundary; the discovery file and env files are 0600 and # must never be mounted into the model sandbox. Model consumers stay # disabled until proven against the sandbox constraints (see # spec/jazz-alpha55-port.md, open items). set -euo pipefail root="${1:?usage: provision-jazz-storage.sh [--force]}" force=0 [[ "${2:-}" == "--force" || "${FORCE:-}" == "1" ]] && force=1 state_dir="$root/.thoughtstream/state" owner_env="$state_dir/jazz.sqlite.server.env" client_env="$root/.thoughtstream/jazz-clients.env" if [[ -f "$owner_env" && $force -ne 1 ]]; then echo "provision: $owner_env already exists; leaving untouched (use --force to regenerate)" >&2 exit 0 fi mkdir -p "$state_dir" port="${JAZZ_SERVER_PORT:-4316}" [[ "$port" =~ ^[0-9]+$ ]] && (( port >= 1 && port <= 65535 )) || { echo "Invalid storage port" >&2; exit 1; } app_id="${JAZZ_APP_ID:-thoughtstream-local}" [[ "$app_id" =~ ^[a-zA-Z0-9_-]+$ ]] || { echo "Invalid app id" >&2; exit 1; } # 256-bit secrets (32 bytes hex). Never use the upstream dev-helper defaults. backend_secret="thoughtstream-backend-$(od -An -N32 -tx1 /dev/urandom | tr -d ' \n')" admin_secret="thoughtstream-admin-$(od -An -N32 -tx1 /dev/urandom | tr -d ' \n')" umask 077 cat > "$owner_env" < "$client_env" <