Initial server source import
This commit is contained in:
@@ -0,0 +1,192 @@
|
||||
# Keychecker Layout
|
||||
|
||||
Normal input and authority:
|
||||
```text
|
||||
PostgreSQL keycheck_candidates fenced provider work queue
|
||||
PostgreSQL keycheck_results authoritative history
|
||||
PostgreSQL keycheck_current_state authoritative current classification
|
||||
D:\truf\runtime\proxy.txt optional provider proxy input
|
||||
```
|
||||
|
||||
`found_secrets.jsonl`, `*Results.jsonl`, and `*Checked.txt`/status files are projector-owned compatibility outputs. They may lag and normal providers do not read or write them.
|
||||
|
||||
Shared helper:
|
||||
```text
|
||||
D:\truf\app\keycheckers\keycheck_common.py
|
||||
```
|
||||
|
||||
`keycheck_runner.py --input-mode postgres` is the default managed mode. `--input` is accepted only with explicit `--input-mode jsonl` for reviewed offline/import compatibility. Provider completion inserts the result, updates current state, completes the exact candidate lease, releases candidate capacity, and creates its projection job in one PostgreSQL transaction.
|
||||
|
||||
## DeepSeek
|
||||
|
||||
```powershell
|
||||
python supervisor.py --config config.yaml --cmd "recheck deepseek all --max-keys 100"
|
||||
```
|
||||
|
||||
Output folder:
|
||||
```text
|
||||
deepseek\deepseekAlive.txt
|
||||
deepseek\deepseekNoBalance.txt
|
||||
deepseek\deepseekDead.txt
|
||||
deepseek\deepseekLimited.txt
|
||||
deepseek\deepseekNetwork.txt
|
||||
deepseek\deepseekUnknown.txt
|
||||
deepseek\deepseekChecked.txt
|
||||
deepseek\deepseekResults.jsonl
|
||||
```
|
||||
|
||||
## Qwen / DashScope
|
||||
|
||||
```powershell
|
||||
python supervisor.py --config config.yaml --cmd "recheck qwen all --max-keys 100"
|
||||
```
|
||||
|
||||
The checker validates `QwenDashScope` findings with `GET /models` against the public DashScope OpenAI-compatible region endpoints. Coding Plan keys (`sk-sp-...`) use `https://coding-intl.dashscope.aliyuncs.com/v1` by default. Workspace-specific endpoints can be added with `--base-url` via `keychecks.service_args.qwen` or `QWEN_BASE_URLS`.
|
||||
|
||||
Output folder:
|
||||
```text
|
||||
qwen\qwenAlive.txt
|
||||
qwen\qwenNoBalance.txt
|
||||
qwen\qwenNoContext.txt
|
||||
qwen\qwenDead.txt
|
||||
qwen\qwenLimited.txt
|
||||
qwen\qwenRestricted.txt
|
||||
qwen\qwenNetwork.txt
|
||||
qwen\qwenUnknown.txt
|
||||
qwen\qwenChecked.txt
|
||||
qwen\qwenResults.jsonl
|
||||
```
|
||||
|
||||
## Kimi / Moonshot AI
|
||||
|
||||
```powershell
|
||||
python supervisor.py --config config.yaml --cmd "recheck kimi all --max-keys 100"
|
||||
```
|
||||
|
||||
The explicit `MOONSHOT_API_KEY` / `KIMI_API_KEY` detector is validated without generation by calling `GET /v1/users/me/balance` on the independent global and China Moonshot endpoints.
|
||||
|
||||
Output folder:
|
||||
```text
|
||||
kimi\kimiAlive.txt
|
||||
kimi\kimiNoBalance.txt
|
||||
kimi\kimiDead.txt
|
||||
kimi\kimiLimited.txt
|
||||
kimi\kimiRestricted.txt
|
||||
kimi\kimiNetwork.txt
|
||||
kimi\kimiUnknown.txt
|
||||
kimi\kimiChecked.txt
|
||||
kimi\kimiResults.jsonl
|
||||
```
|
||||
|
||||
## Groq
|
||||
|
||||
```powershell
|
||||
python supervisor.py --config config.yaml --cmd "recheck groq all --max-keys 100"
|
||||
```
|
||||
|
||||
The checker validates TruffleHog `Groq` findings with `GET https://api.groq.com/openai/v1/models` and does not run generation probes.
|
||||
|
||||
Output folder:
|
||||
```text
|
||||
groq\groqAlive.txt
|
||||
groq\groqDead.txt
|
||||
groq\groqLimited.txt
|
||||
groq\groqRestricted.txt
|
||||
groq\groqNetwork.txt
|
||||
groq\groqUnknown.txt
|
||||
groq\groqChecked.txt
|
||||
groq\groqResults.jsonl
|
||||
```
|
||||
|
||||
## Replicate / xAI / HuggingFace
|
||||
|
||||
```powershell
|
||||
python supervisor.py --config config.yaml --cmd "recheck replicate all --max-keys 100"
|
||||
python supervisor.py --config config.yaml --cmd "recheck xai all --max-keys 100"
|
||||
python supervisor.py --config config.yaml --cmd "recheck huggingface all --max-keys 100"
|
||||
```
|
||||
|
||||
These checkers validate built-in TruffleHog findings through non-generating endpoints: Replicate account lookup, xAI model list, and HuggingFace whoami.
|
||||
|
||||
## Anthropic
|
||||
|
||||
```powershell
|
||||
python supervisor.py --config config.yaml --cmd "recheck anthropic all --max-keys 100"
|
||||
```
|
||||
|
||||
Output folder:
|
||||
```text
|
||||
anthropic\anthropicAlive.txt
|
||||
anthropic\anthropicNoQuota.txt
|
||||
anthropic\anthropicDead.txt
|
||||
anthropic\anthropicLimited.txt
|
||||
anthropic\anthropicRestricted.txt
|
||||
anthropic\anthropicNetwork.txt
|
||||
anthropic\anthropicUnknown.txt
|
||||
anthropic\anthropicChecked.txt
|
||||
anthropic\anthropicResults.jsonl
|
||||
```
|
||||
|
||||
## AWS
|
||||
|
||||
Default mode only checks STS identity:
|
||||
```powershell
|
||||
python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"
|
||||
```
|
||||
|
||||
Optional Bedrock probing is configured under `keychecks.service_args.aws`, then run:
|
||||
```powershell
|
||||
python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"
|
||||
```
|
||||
|
||||
Output folder:
|
||||
```text
|
||||
aws\awsAlive.txt
|
||||
aws\awsBedrock.txt
|
||||
aws\awsAdmin.txt
|
||||
aws\awsCanary.txt
|
||||
aws\awsQuarantined.txt
|
||||
aws\awsAccessDenied.txt
|
||||
aws\awsDead.txt
|
||||
aws\awsNetwork.txt
|
||||
aws\awsUnknown.txt
|
||||
aws\awsChecked.txt
|
||||
aws\awsResults.jsonl
|
||||
```
|
||||
|
||||
Canary AWS credentials are detected before active AWS probes when TruffleHog provides `ExtraData.is_canary` / canary message. If metadata is absent, STS ARN containing `canarytokens` is also classified as `awsCanary.txt` and IAM/Bedrock probes are skipped.
|
||||
|
||||
## Azure
|
||||
|
||||
```powershell
|
||||
python supervisor.py --config config.yaml --cmd "recheck azure all --max-keys 100"
|
||||
```
|
||||
|
||||
This checks Azure service-principal findings from `DetectorName=Azure` using `tenantId`, `clientId`, `clientSecret` from `RawV2`.
|
||||
|
||||
`DetectorName=AzureOpenAI` is placed into `azureOpenAIUnresolved.txt` unless an endpoint/resource name is available.
|
||||
|
||||
Output folder:
|
||||
```text
|
||||
azure\azureAlive.txt
|
||||
azure\azureDead.txt
|
||||
azure\azureRestricted.txt
|
||||
azure\azureNetwork.txt
|
||||
azure\azureUnknown.txt
|
||||
azure\azureOpenAIUnresolved.txt
|
||||
azure\azureChecked.txt
|
||||
azure\azureResults.jsonl
|
||||
```
|
||||
|
||||
## Retry Flags
|
||||
|
||||
Common flags:
|
||||
```text
|
||||
--retry-network
|
||||
--retry-limited
|
||||
--retry-unknown
|
||||
--recheck-all
|
||||
--max-keys N
|
||||
```
|
||||
|
||||
Network/proxy failures are committed with the `network` status group and can be selected for a bounded PostgreSQL recheck. `*Network.txt` is only its asynchronous compatibility projection.
|
||||
Reference in New Issue
Block a user