basquetWi + New ticket
pluto PLUTO-634

Scheduled GoTrue config-drift check (cron/applog rail, alerts not blocks)

In progress normal cpcoder-pluto-cc

Follow-up to PLUTO-633: the push-time gate (scripts/assert-authconfig.mjs) only fires when someone pushes AND holds the PAT -- real drift on pluto's Supabase Auth config could sit live for days between pushes with nobody knowing. Wire the same assert script into a scheduled check (cron/applog alert rail) that ALERTS on mismatch instead of blocking a push. Script already exits 1 + prints a diff on real drift -- should drop in directly, same field-select/secret-safety properties as PLUTO-633. Non-urgent, backlog.

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • wi-cli-venus created · 2w ago
  • wi-cli-venus assigned · 2w ago
    coder-pluto-cc
  • wi-cli-venus note · 2w ago
    Built: --alert mode on scripts/assert-authconfig.mjs (+138/-8, unpushed) + systemd user units pluto-authconfig-drift.{service,timer} on venus, daily 08:10 UTC, enabled, one manual run green (7/7 fields match). Host timer not Vercel cron: the Management-API PAT is account-wide/unscopeable, keeping it off prod runtime env. Drift emails the field diff; a SKIP escalates only after 72h with no successful read. Blocked on INTERNAL_EMAIL_KEY (Vercel Sensitive, unpullable) - asked pm-pluto-cc. Class-A pre-push diff review with audit-pluto-ca (coder-pluto-cc-msaalp47mei6).
  • wi-cli-venus statusChanged · 2w ago
    Implemented + timer live; holding push on audit PASS + INTERNAL_EMAIL_KEY
  • wi-cli-venus note · 2w ago
    PUSHED 7fbbff2 v2.22.52, live version-match confirmed (api/app-version 2.22.52, dpl_5AS4Xz2wFp8CYVnPt3CpgRafoKAs). audit-pluto-ca PASS x2 (msaaouv25g7o main diff, msaas1f5ra73 --test-alert delta). Registry rows 93/94 filed by bin-venus-cc, maintainer coder-pluto-cc, backup db-pluto-cc; unit-file/timer/EnvironmentFile plumbing routes to nw-venus-cc per row-38 lane split. REMAINING (WI stays open): the alert leg is UNTESTED, not merely undeliverable - no run has ever entered the email path since none has found drift. Needs (a) INTERNAL_EMAIL_KEY provisioned by Elazar via pm-pluto-cc, (b) one [TEST]-labelled send via --alert --test-alert, (c) a forced throwaway-field drift to exercise detection->mail end to end. Note for future journal readers: the 2026-08-01 11:34:56Z exit-1 run ('AUTHCONFIG_SPEC_PATH set in the runner env - refusing') was me deliberately injecting a drop-in to prove the ExecStartPre guard fails the unit; drop-in removed, clean rerun 1s later. Not a defect.
task
2w ago by wi-cli-venus
2w ago