Initial server source import

This commit is contained in:
sashatrask
2026-09-30 20:30:56 +03:00
commit 170dd941b9
498 changed files with 261563 additions and 0 deletions
+192
View File
@@ -0,0 +1,192 @@
# Keychecker Layout
Normal input and authority:
```text
PostgreSQL keycheck_candidates fenced provider work queue
PostgreSQL keycheck_results authoritative history
PostgreSQL keycheck_current_state authoritative current classification
D:\truf\runtime\proxy.txt optional provider proxy input
```
`found_secrets.jsonl`, `*Results.jsonl`, and `*Checked.txt`/status files are projector-owned compatibility outputs. They may lag and normal providers do not read or write them.
Shared helper:
```text
D:\truf\app\keycheckers\keycheck_common.py
```
`keycheck_runner.py --input-mode postgres` is the default managed mode. `--input` is accepted only with explicit `--input-mode jsonl` for reviewed offline/import compatibility. Provider completion inserts the result, updates current state, completes the exact candidate lease, releases candidate capacity, and creates its projection job in one PostgreSQL transaction.
## DeepSeek
```powershell
python supervisor.py --config config.yaml --cmd "recheck deepseek all --max-keys 100"
```
Output folder:
```text
deepseek\deepseekAlive.txt
deepseek\deepseekNoBalance.txt
deepseek\deepseekDead.txt
deepseek\deepseekLimited.txt
deepseek\deepseekNetwork.txt
deepseek\deepseekUnknown.txt
deepseek\deepseekChecked.txt
deepseek\deepseekResults.jsonl
```
## Qwen / DashScope
```powershell
python supervisor.py --config config.yaml --cmd "recheck qwen all --max-keys 100"
```
The checker validates `QwenDashScope` findings with `GET /models` against the public DashScope OpenAI-compatible region endpoints. Coding Plan keys (`sk-sp-...`) use `https://coding-intl.dashscope.aliyuncs.com/v1` by default. Workspace-specific endpoints can be added with `--base-url` via `keychecks.service_args.qwen` or `QWEN_BASE_URLS`.
Output folder:
```text
qwen\qwenAlive.txt
qwen\qwenNoBalance.txt
qwen\qwenNoContext.txt
qwen\qwenDead.txt
qwen\qwenLimited.txt
qwen\qwenRestricted.txt
qwen\qwenNetwork.txt
qwen\qwenUnknown.txt
qwen\qwenChecked.txt
qwen\qwenResults.jsonl
```
## Kimi / Moonshot AI
```powershell
python supervisor.py --config config.yaml --cmd "recheck kimi all --max-keys 100"
```
The explicit `MOONSHOT_API_KEY` / `KIMI_API_KEY` detector is validated without generation by calling `GET /v1/users/me/balance` on the independent global and China Moonshot endpoints.
Output folder:
```text
kimi\kimiAlive.txt
kimi\kimiNoBalance.txt
kimi\kimiDead.txt
kimi\kimiLimited.txt
kimi\kimiRestricted.txt
kimi\kimiNetwork.txt
kimi\kimiUnknown.txt
kimi\kimiChecked.txt
kimi\kimiResults.jsonl
```
## Groq
```powershell
python supervisor.py --config config.yaml --cmd "recheck groq all --max-keys 100"
```
The checker validates TruffleHog `Groq` findings with `GET https://api.groq.com/openai/v1/models` and does not run generation probes.
Output folder:
```text
groq\groqAlive.txt
groq\groqDead.txt
groq\groqLimited.txt
groq\groqRestricted.txt
groq\groqNetwork.txt
groq\groqUnknown.txt
groq\groqChecked.txt
groq\groqResults.jsonl
```
## Replicate / xAI / HuggingFace
```powershell
python supervisor.py --config config.yaml --cmd "recheck replicate all --max-keys 100"
python supervisor.py --config config.yaml --cmd "recheck xai all --max-keys 100"
python supervisor.py --config config.yaml --cmd "recheck huggingface all --max-keys 100"
```
These checkers validate built-in TruffleHog findings through non-generating endpoints: Replicate account lookup, xAI model list, and HuggingFace whoami.
## Anthropic
```powershell
python supervisor.py --config config.yaml --cmd "recheck anthropic all --max-keys 100"
```
Output folder:
```text
anthropic\anthropicAlive.txt
anthropic\anthropicNoQuota.txt
anthropic\anthropicDead.txt
anthropic\anthropicLimited.txt
anthropic\anthropicRestricted.txt
anthropic\anthropicNetwork.txt
anthropic\anthropicUnknown.txt
anthropic\anthropicChecked.txt
anthropic\anthropicResults.jsonl
```
## AWS
Default mode only checks STS identity:
```powershell
python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"
```
Optional Bedrock probing is configured under `keychecks.service_args.aws`, then run:
```powershell
python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"
```
Output folder:
```text
aws\awsAlive.txt
aws\awsBedrock.txt
aws\awsAdmin.txt
aws\awsCanary.txt
aws\awsQuarantined.txt
aws\awsAccessDenied.txt
aws\awsDead.txt
aws\awsNetwork.txt
aws\awsUnknown.txt
aws\awsChecked.txt
aws\awsResults.jsonl
```
Canary AWS credentials are detected before active AWS probes when TruffleHog provides `ExtraData.is_canary` / canary message. If metadata is absent, STS ARN containing `canarytokens` is also classified as `awsCanary.txt` and IAM/Bedrock probes are skipped.
## Azure
```powershell
python supervisor.py --config config.yaml --cmd "recheck azure all --max-keys 100"
```
This checks Azure service-principal findings from `DetectorName=Azure` using `tenantId`, `clientId`, `clientSecret` from `RawV2`.
`DetectorName=AzureOpenAI` is placed into `azureOpenAIUnresolved.txt` unless an endpoint/resource name is available.
Output folder:
```text
azure\azureAlive.txt
azure\azureDead.txt
azure\azureRestricted.txt
azure\azureNetwork.txt
azure\azureUnknown.txt
azure\azureOpenAIUnresolved.txt
azure\azureChecked.txt
azure\azureResults.jsonl
```
## Retry Flags
Common flags:
```text
--retry-network
--retry-limited
--retry-unknown
--recheck-all
--max-keys N
```
Network/proxy failures are committed with the `network` status group and can be selected for a bounded PostgreSQL recheck. `*Network.txt` is only its asynchronous compatibility projection.