Files
monky-deployd/pyproject.toml
T
mdella b25c6b3b8b feat: pull private images without a hand docker login; surface the pull error
Design merged first: monky-design-docs !225 (doc 24 §4a). Pairs with monky-tenancy!40, which
copies the estate-wide read-only Harbor robot into each environment's own prefix and marks the
manifest entry `use: registry-auth`.

- That entry is not an env var (it would otherwise land in .env and therefore in every container's
  environment). The agent parses it — JSON, or `username:password` with the new `registry_host` —
  and writes `<state_dir>/docker/config.json` 0600 in a directory it owns, with an explicit
  DOCKER_CONFIG pointing the docker CLI at it. The unit runs as monky-deployd, so a `docker login`
  by a human or by root is invisible to the agent: that is what made env-dev-01 look like it had no
  credential at all after the operator had just logged in.
- `compose pull` failures now carry the registry's own message ("no basic auth credentials",
  "manifest unknown", DNS) into the journal and the report instead of `rc=1`.
- Tests: both credential shapes, the refusals, 0600/0700 modes, idempotent rewrite, and that the
  runner never silently falls back to a human's $HOME.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLB7jieMNRkTsJ2epr4Ds1
2026-09-08 15:45:22 +00:00

40 lines
1.0 KiB
TOML

[build-system]
requires = ["setuptools>=68"]
build-backend = "setuptools.build_meta"
[project]
name = "monky-deployd"
version = "0.1.7"
description = "Monky backend pull agent: checkin -> bundle -> lease -> OpenBao -> docker compose -> report, over the ziti mesh (MONKY-ADR-0028)"
readme = "README.md"
requires-python = ">=3.12"
license = { text = "Proprietary" }
authors = [{ name = "Tikali", email = "mdella@tikali.ai" }]
dependencies = [] # stdlib only; `openziti` is optional (transport: sdk) and vendored by CI
[project.optional-dependencies]
sdk = ["openziti>=1.0"]
dev = ["pytest>=8", "ruff>=0.16,<0.17"]
[project.scripts]
monky-deployd = "monky_deployd.cli:main"
[tool.setuptools.packages.find]
include = ["monky_deployd*"]
[tool.ruff]
line-length = 120
target-version = "py312"
extend-exclude = ["ansible", "packaging"]
[tool.ruff.lint]
select = ["E", "F", "I", "UP", "B", "W"]
ignore = ["E501"]
[tool.ruff.lint.per-file-ignores]
"tests/*" = ["B011"]
[tool.pytest.ini_options]
testpaths = ["tests"]
addopts = "-q"