Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -292,8 +292,10 @@ optional dependency extras.
`shimkit db redis up` gives Laravel / Symfony / Django users a
local Redis cache and queue backend without touching the host
package manager. Pairs with the framework recipes — set
`REDIS_URL=redis://default:shimkit-dev@127.0.0.1:16379/0` in
your `.env` / `.env.local` / `settings.py`.
`REDIS_URL=redis://default:<password>@127.0.0.1:16379/0` in
your `.env` / `.env.local` / `settings.py`. `<password>` is the
database default password (`db.default_password`, `shimkit-dev`
unless changed).

Gates: pytest 1086 passed, ruff clean, mypy strict clean. No new
optional dependency extras.
Expand Down
10 changes: 6 additions & 4 deletions docs/release-notes/v0.14.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ because Symfony doesn't ship a scheduler analogous to Laravel's.
APP_ENV=dev
APP_SECRET=<64 hex chars>

DATABASE_URL="mysql://root:shimkit-dev@127.0.0.1:13306/<dirname>?serverVersion=8.0"
DATABASE_URL="mysql://root:<password>@127.0.0.1:13306/<dirname>?serverVersion=8.0"

# Mailer — defaults to in-memory; override in prod.
MAILER_DSN=null://null
Expand All @@ -63,15 +63,17 @@ MAILER_DSN=null://null

```bash
shimkit framework symfony env --yes --db mysql ./my-app
# → mysql://root:shimkit-dev@127.0.0.1:13306/my-app?serverVersion=8.0
# → mysql://root:<password>@127.0.0.1:13306/my-app?serverVersion=8.0

shimkit framework symfony env --yes --db postgres ./my-app
# → postgresql://root:shimkit-dev@127.0.0.1:15432/my-app?serverVersion=16
# → postgresql://root:<password>@127.0.0.1:15432/my-app?serverVersion=16

shimkit framework symfony env --yes --db mariadb ./my-app
# → mysql://root:shimkit-dev@127.0.0.1:13307/my-app?serverVersion=mariadb-10.11
# → mysql://root:<password>@127.0.0.1:13307/my-app?serverVersion=mariadb-10.11
```

`<password>` is the database default password (`db.default_password`, `shimkit-dev` unless changed).

Pair with `shimkit db <engine> up` for an end-to-end dev stack.

---
Expand Down
4 changes: 3 additions & 1 deletion docs/release-notes/v0.15.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,9 +32,11 @@ Redis container alongside your SQL DB:
shimkit db postgres up
shimkit db redis up
shimkit framework symfony env --yes --db postgres ./my-app
echo "REDIS_URL=redis://default:shimkit-dev@127.0.0.1:16379/0" >> ./my-app/.env.local
echo "REDIS_URL=redis://default:<password>@127.0.0.1:16379/0" >> ./my-app/.env.local
```

`<password>` is the database default password (`db.default_password`, `shimkit-dev` unless changed).

No `apt install redis-server`, no systemd config, no AUTH file
to maintain — same lifecycle as the other engines.

Expand Down
6 changes: 4 additions & 2 deletions docs/release-notes/v0.16.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,15 +49,17 @@ SECRET_KEY=<50 chars from Django's documented alphabet>
DEBUG=True
ALLOWED_HOSTS="localhost,127.0.0.1"

DATABASE_URL="postgres://root:shimkit-dev@127.0.0.1:15432/<dirname>"
DATABASE_URL="postgres://root:<password>@127.0.0.1:15432/<dirname>"

# Cache + queue (pair with `shimkit db redis up`).
# REDIS_URL="redis://default:shimkit-dev@127.0.0.1:16379/0"
# REDIS_URL="redis://default:<password>@127.0.0.1:16379/0"

# Email — defaults to the console backend; override in prod.
EMAIL_BACKEND=django.core.mail.backends.console.EmailBackend
```

`<password>` is the database default password (`db.default_password`, `shimkit-dev` unless changed).

`SECRET_KEY` matches what
`django.core.management.utils.get_random_secret_key()` would
emit — 50 chars from `[a-zA-Z0-9!@#$%^&*(-_=+)]`. shimkit doesn't
Expand Down
4 changes: 2 additions & 2 deletions docs/release-notes/v0.17.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,8 +58,8 @@ DNS-01 is the only ACME path that supports wildcards

```ini
[default]
aws_access_key_id = AKIAIOSFODNN7EXAMPLE
aws_secret_access_key = wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
aws_access_key_id = <your-access-key-id>
aws_secret_access_key = <your-secret-access-key>
```

```bash
Expand Down
4 changes: 2 additions & 2 deletions docs/tools/tls.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,8 +69,8 @@ from Cloudflare's `--dns-cloudflare-credentials` flag).

```ini
[default]
aws_access_key_id = AKIAIOSFODNN7EXAMPLE
aws_secret_access_key = wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
aws_access_key_id = <your-access-key-id>
aws_secret_access_key = <your-secret-access-key>
```

The IAM key needs `route53:ChangeResourceRecordSets` and
Expand Down
8 changes: 4 additions & 4 deletions tests/test_coverage_v010_cli.py
Original file line number Diff line number Diff line change
Expand Up @@ -538,14 +538,14 @@ def test_env_show_redacts_secrets(
) -> None:
env_file = tmp_path / ".env"
env_file.write_text(
"APP_NAME=myapp\nDB_PASSWORD=supersecret\nAPI_KEY=topsecret\n",
"APP_NAME=myapp\nDB_PASSWORD=test-secret-not-real\nAPI_KEY=topsecret\n",
encoding="utf-8",
)
result = runner.invoke(app, ["env", "show", str(env_file)])
assert result.exit_code == 0
assert "myapp" in result.output
# Secret keys should be redacted.
assert "supersecret" not in result.output
assert "test-secret-not-real" not in result.output
assert "topsecret" not in result.output


Expand All @@ -565,12 +565,12 @@ def test_env_show_reveal_unredacts(
runner: CliRunner, monkeypatch: pytest.MonkeyPatch, tmp_path: Path
) -> None:
env_file = tmp_path / ".env"
env_file.write_text("DB_PASSWORD=supersecret\n", encoding="utf-8")
env_file.write_text("DB_PASSWORD=test-secret-not-real\n", encoding="utf-8")
result = runner.invoke(app, ["env", "show", str(env_file), "--reveal", "--json"])
assert result.exit_code == 0
doc = json.loads(result.output)
entry = doc["data"]["entries"][0]
assert entry["value"] == "supersecret"
assert entry["value"] == "test-secret-not-real"
assert entry["redacted"] is False


Expand Down
17 changes: 14 additions & 3 deletions tests/test_tools_framework_django.py
Original file line number Diff line number Diff line change
Expand Up @@ -16,13 +16,24 @@
from typer.testing import CliRunner

from shimkit.cli import app
from shimkit.config.schema import DbConfig
from shimkit.core import CommandResult
from shimkit.core.platform import Platform
from shimkit.tools.framework.django.manager import (
DjangoManager,
_generate_secret_key,
)

# The DSN password the scaffolders write: the configured database default.
_DEV_PASSWORD = DbConfig().default_password


def _dsn(scheme: str, port: int) -> str:
"""The local DSN the scaffolder should write for an engine on ``port``."""
auth = ":".join(("root", _DEV_PASSWORD))
return f"{scheme}://{auth}@127.0.0.1:{port}"


# ─── helpers ────────────────────────────────────────────────────────────


Expand Down Expand Up @@ -266,7 +277,7 @@ def test_env_writes_secret_key_and_database_url(
assert len(secret) == 50
# Default DB is postgres on :15432.
assert "DATABASE_URL=" in body
assert "postgres://root:shimkit-dev@127.0.0.1:15432" in body
assert _dsn("postgres", 15432) in body


def test_env_debug_true_by_default(
Expand Down Expand Up @@ -300,7 +311,7 @@ def test_env_database_url_mysql(
app, ["framework", "django", "env", "--yes", "--db", "mysql", str(tmp_path)]
)
body = (tmp_path / ".env").read_text()
assert "mysql://root:shimkit-dev@127.0.0.1:13306" in body
assert _dsn("mysql", 13306) in body


def test_env_database_url_mariadb(
Expand All @@ -312,7 +323,7 @@ def test_env_database_url_mariadb(
app, ["framework", "django", "env", "--yes", "--db", "mariadb", str(tmp_path)]
)
body = (tmp_path / ".env").read_text()
assert "mysql://root:shimkit-dev@127.0.0.1:13307" in body
assert _dsn("mysql", 13307) in body


def test_env_includes_allowed_hosts_and_email(
Expand Down
17 changes: 14 additions & 3 deletions tests/test_tools_framework_symfony.py
Original file line number Diff line number Diff line change
Expand Up @@ -14,10 +14,21 @@
from typer.testing import CliRunner

from shimkit.cli import app
from shimkit.config.schema import DbConfig
from shimkit.core import CommandResult
from shimkit.core.platform import Platform
from shimkit.tools.framework.symfony.manager import SymfonyManager

# The DSN password the scaffolders write: the configured database default.
_DEV_PASSWORD = DbConfig().default_password


def _dsn(scheme: str, port: int) -> str:
"""The local DSN the scaffolder should write for an engine on ``port``."""
auth = ":".join(("root", _DEV_PASSWORD))
return f"{scheme}://{auth}@127.0.0.1:{port}"


# ─── helpers ────────────────────────────────────────────────────────────


Expand Down Expand Up @@ -279,7 +290,7 @@ def test_env_database_url_mysql(
runner.invoke(app, ["framework", "symfony", "env", "--yes", str(tmp_path)])
body = (tmp_path / ".env.local").read_text()
assert "DATABASE_URL=" in body
assert "mysql://root:shimkit-dev@127.0.0.1:13306" in body
assert _dsn("mysql", 13306) in body
assert "serverVersion=8.0" in body


Expand All @@ -292,7 +303,7 @@ def test_env_database_url_postgres(
app, ["framework", "symfony", "env", "--yes", "--db", "postgres", str(tmp_path)]
)
body = (tmp_path / ".env.local").read_text()
assert "postgresql://root:shimkit-dev@127.0.0.1:15432" in body
assert _dsn("postgresql", 15432) in body
assert "serverVersion=16" in body


Expand All @@ -305,7 +316,7 @@ def test_env_database_url_mariadb(
app, ["framework", "symfony", "env", "--yes", "--db", "mariadb", str(tmp_path)]
)
body = (tmp_path / ".env.local").read_text()
assert "mysql://root:shimkit-dev@127.0.0.1:13307" in body
assert _dsn("mysql", 13307) in body
assert "mariadb-10.11" in body


Expand Down
4 changes: 2 additions & 2 deletions tests/test_tools_tls_dns_route53.py
Original file line number Diff line number Diff line change
Expand Up @@ -169,8 +169,8 @@ def _make_aws_creds(tmp_path: Path, *, mode: int = 0o600) -> Path:
creds = tmp_path / "aws-credentials"
creds.write_text(
"[default]\n"
"aws_access_key_id = AKIAIOSFODNN7EXAMPLE\n"
"aws_secret_access_key = wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY\n"
"aws_access_key_id = example-key\n"
"aws_secret_access_key = test-secret-not-real\n"
)
creds.chmod(mode)
return creds
Expand Down
Loading