193 lines
5.5 KiB
Markdown
193 lines
5.5 KiB
Markdown
# Keychecker Layout
|
|
|
|
Normal input and authority:
|
|
```text
|
|
PostgreSQL keycheck_candidates fenced provider work queue
|
|
PostgreSQL keycheck_results authoritative history
|
|
PostgreSQL keycheck_current_state authoritative current classification
|
|
D:\truf\runtime\proxy.txt optional provider proxy input
|
|
```
|
|
|
|
`found_secrets.jsonl`, `*Results.jsonl`, and `*Checked.txt`/status files are projector-owned compatibility outputs. They may lag and normal providers do not read or write them.
|
|
|
|
Shared helper:
|
|
```text
|
|
D:\truf\app\keycheckers\keycheck_common.py
|
|
```
|
|
|
|
`keycheck_runner.py --input-mode postgres` is the default managed mode. `--input` is accepted only with explicit `--input-mode jsonl` for reviewed offline/import compatibility. Provider completion inserts the result, updates current state, completes the exact candidate lease, releases candidate capacity, and creates its projection job in one PostgreSQL transaction.
|
|
|
|
## DeepSeek
|
|
|
|
```powershell
|
|
python supervisor.py --config config.yaml --cmd "recheck deepseek all --max-keys 100"
|
|
```
|
|
|
|
Output folder:
|
|
```text
|
|
deepseek\deepseekAlive.txt
|
|
deepseek\deepseekNoBalance.txt
|
|
deepseek\deepseekDead.txt
|
|
deepseek\deepseekLimited.txt
|
|
deepseek\deepseekNetwork.txt
|
|
deepseek\deepseekUnknown.txt
|
|
deepseek\deepseekChecked.txt
|
|
deepseek\deepseekResults.jsonl
|
|
```
|
|
|
|
## Qwen / DashScope
|
|
|
|
```powershell
|
|
python supervisor.py --config config.yaml --cmd "recheck qwen all --max-keys 100"
|
|
```
|
|
|
|
The checker validates `QwenDashScope` findings with `GET /models` against the public DashScope OpenAI-compatible region endpoints. Coding Plan keys (`sk-sp-...`) use `https://coding-intl.dashscope.aliyuncs.com/v1` by default. Workspace-specific endpoints can be added with `--base-url` via `keychecks.service_args.qwen` or `QWEN_BASE_URLS`.
|
|
|
|
Output folder:
|
|
```text
|
|
qwen\qwenAlive.txt
|
|
qwen\qwenNoBalance.txt
|
|
qwen\qwenNoContext.txt
|
|
qwen\qwenDead.txt
|
|
qwen\qwenLimited.txt
|
|
qwen\qwenRestricted.txt
|
|
qwen\qwenNetwork.txt
|
|
qwen\qwenUnknown.txt
|
|
qwen\qwenChecked.txt
|
|
qwen\qwenResults.jsonl
|
|
```
|
|
|
|
## Kimi / Moonshot AI
|
|
|
|
```powershell
|
|
python supervisor.py --config config.yaml --cmd "recheck kimi all --max-keys 100"
|
|
```
|
|
|
|
The explicit `MOONSHOT_API_KEY` / `KIMI_API_KEY` detector is validated without generation by calling `GET /v1/users/me/balance` on the independent global and China Moonshot endpoints.
|
|
|
|
Output folder:
|
|
```text
|
|
kimi\kimiAlive.txt
|
|
kimi\kimiNoBalance.txt
|
|
kimi\kimiDead.txt
|
|
kimi\kimiLimited.txt
|
|
kimi\kimiRestricted.txt
|
|
kimi\kimiNetwork.txt
|
|
kimi\kimiUnknown.txt
|
|
kimi\kimiChecked.txt
|
|
kimi\kimiResults.jsonl
|
|
```
|
|
|
|
## Groq
|
|
|
|
```powershell
|
|
python supervisor.py --config config.yaml --cmd "recheck groq all --max-keys 100"
|
|
```
|
|
|
|
The checker validates TruffleHog `Groq` findings with `GET https://api.groq.com/openai/v1/models` and does not run generation probes.
|
|
|
|
Output folder:
|
|
```text
|
|
groq\groqAlive.txt
|
|
groq\groqDead.txt
|
|
groq\groqLimited.txt
|
|
groq\groqRestricted.txt
|
|
groq\groqNetwork.txt
|
|
groq\groqUnknown.txt
|
|
groq\groqChecked.txt
|
|
groq\groqResults.jsonl
|
|
```
|
|
|
|
## Replicate / xAI / HuggingFace
|
|
|
|
```powershell
|
|
python supervisor.py --config config.yaml --cmd "recheck replicate all --max-keys 100"
|
|
python supervisor.py --config config.yaml --cmd "recheck xai all --max-keys 100"
|
|
python supervisor.py --config config.yaml --cmd "recheck huggingface all --max-keys 100"
|
|
```
|
|
|
|
These checkers validate built-in TruffleHog findings through non-generating endpoints: Replicate account lookup, xAI model list, and HuggingFace whoami.
|
|
|
|
## Anthropic
|
|
|
|
```powershell
|
|
python supervisor.py --config config.yaml --cmd "recheck anthropic all --max-keys 100"
|
|
```
|
|
|
|
Output folder:
|
|
```text
|
|
anthropic\anthropicAlive.txt
|
|
anthropic\anthropicNoQuota.txt
|
|
anthropic\anthropicDead.txt
|
|
anthropic\anthropicLimited.txt
|
|
anthropic\anthropicRestricted.txt
|
|
anthropic\anthropicNetwork.txt
|
|
anthropic\anthropicUnknown.txt
|
|
anthropic\anthropicChecked.txt
|
|
anthropic\anthropicResults.jsonl
|
|
```
|
|
|
|
## AWS
|
|
|
|
Default mode only checks STS identity:
|
|
```powershell
|
|
python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"
|
|
```
|
|
|
|
Optional Bedrock probing is configured under `keychecks.service_args.aws`, then run:
|
|
```powershell
|
|
python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"
|
|
```
|
|
|
|
Output folder:
|
|
```text
|
|
aws\awsAlive.txt
|
|
aws\awsBedrock.txt
|
|
aws\awsAdmin.txt
|
|
aws\awsCanary.txt
|
|
aws\awsQuarantined.txt
|
|
aws\awsAccessDenied.txt
|
|
aws\awsDead.txt
|
|
aws\awsNetwork.txt
|
|
aws\awsUnknown.txt
|
|
aws\awsChecked.txt
|
|
aws\awsResults.jsonl
|
|
```
|
|
|
|
Canary AWS credentials are detected before active AWS probes when TruffleHog provides `ExtraData.is_canary` / canary message. If metadata is absent, STS ARN containing `canarytokens` is also classified as `awsCanary.txt` and IAM/Bedrock probes are skipped.
|
|
|
|
## Azure
|
|
|
|
```powershell
|
|
python supervisor.py --config config.yaml --cmd "recheck azure all --max-keys 100"
|
|
```
|
|
|
|
This checks Azure service-principal findings from `DetectorName=Azure` using `tenantId`, `clientId`, `clientSecret` from `RawV2`.
|
|
|
|
`DetectorName=AzureOpenAI` is placed into `azureOpenAIUnresolved.txt` unless an endpoint/resource name is available.
|
|
|
|
Output folder:
|
|
```text
|
|
azure\azureAlive.txt
|
|
azure\azureDead.txt
|
|
azure\azureRestricted.txt
|
|
azure\azureNetwork.txt
|
|
azure\azureUnknown.txt
|
|
azure\azureOpenAIUnresolved.txt
|
|
azure\azureChecked.txt
|
|
azure\azureResults.jsonl
|
|
```
|
|
|
|
## Retry Flags
|
|
|
|
Common flags:
|
|
```text
|
|
--retry-network
|
|
--retry-limited
|
|
--retry-unknown
|
|
--recheck-all
|
|
--max-keys N
|
|
```
|
|
|
|
Network/proxy failures are committed with the `network` status group and can be selected for a bounded PostgreSQL recheck. `*Network.txt` is only its asynchronous compatibility projection.
|