Skip to content

chore(genai-stack): retire the IIS auth and API-key rewrite scripts (out of repo scope) - #18838

Merged
myia-ai-01 merged 3 commits into
mainfrom
fix/iis-auth-drop-unrelated-site
Oct 2, 2026
Merged

myia-ai-01 merged 3 commits into
mainfrom
fix/iis-auth-drop-unrelated-site

Conversation

@jsboige

@jsboige jsboige commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Résumé

L'authentification IIS relève de l'infrastructure d'hébergement, pas du dépôt du cours : décision du mainteneur. Cette PR touche 5 fichiers : elle retire les scripts qui la configuraient et met à jour deux README.

Fichier Rôle Sort
scripts/genai-stack/Configure-IISAuthentication.ps1 authentification Basic IIS sur 22 services retiré
scripts/genai-stack/Manage-ApiKeys.ps1 génère des clés API et écrit des règles de réécriture d'URL IIS pour les valider retiré
scripts/genai-stack/Manage-ApiKeys.sh jumeau bash du précédent (#10644) retiré
scripts/README.md, scripts/environment/README.md citaient le script IIS comme seul cas Windows-only phrase mise à jour

Le premier commit de la branche retirait seulement une entrée du premier script (sans effet : la liste n'était jamais lue). Le second retire le script entier.

Pourquoi c'est sûr

Préservation

Les scripts retirés restent dans l'historique de main, à 82bcea5ed595ed81686eaecca0c66154d167a8d3 :

  • Configure-IISAuthentication.ps1 : blob 5579d7d3c3
  • Manage-ApiKeys.ps1 : blob 0841537f98
  • Manage-ApiKeys.sh : blob a726e803d1

Récupération : git show 82bcea5ed5:scripts/genai-stack/<fichier>.

Ils sont proposés au workspace qui gère l'IIS et SearXNG, qui décidera s'il les reprend.

Closes #18839

Grain: LIGHT/hygiene — lane myia-ai-01:CoursIA — prev: #18833

🤖 Generated with Claude Code

…vice inventory

The entry sat in $SecuredServices, an inventory list the script never
reads (Audit/Configure/Test only iterate $UIServices and $APIServices),
so removing it changes no behavior.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added variation-tag-genre-offlist GENRE hors de l'enumeration variation-protocol §1 variation-tag-prev-absent Tag Grain sans 'prev: <TIER>/<GENRE> #<PR>' (adjacence G-VAR-3 inevaluable) variation-light-cap-reached Lane ayant deja merge une LIGHT aujourd'hui (cap G-VAR-2 atteint) labels Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

G-VAR-2 light cap reached (advisory, non bloquant).
La lane myia-ai-01:CoursIA a deja consomme son budget LIGHT du jour (#18597 (merge a 2026-10-02T02:19:22Z)).
G-VAR-2 plafonne a max(1, grains_mergees_du_jour // 3) LIGHT par lane et par jour,
toutes categories LIGHT confondues
(guard, doc, refs, ... partagent un seul budget) :
c'est un RATIO, pas un plafond plat. La decision de merge reste au coordinateur.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

G-VAR-2/3 GENRE signals (advisory, non bloquant, #10020).
La lane `myia-ai-01:CoursIA` voit ces signaux actifs sur les mergees du jour (UTC 2026-10-02) :

G-VAR-2 plafonne a max(1, grains_mergees_du_jour // 3) LIGHT par lane et par jour, toutes categories LIGHT confondues -- un RATIO, pas un plafond plat ; le cap calcule du jour est dans le tally ci-dessus. G-VAR-3 interdit deux genres LIGHT consecutifs. Les signaux ci-dessus rendent le fait VISIBLE (labels variation-tier-inflation, `variation-genre-run`, `variation-genre-cap-exceeded`, `variation-genre-mismatch`, `variation-genre-unknown`) -- la decision de merge reste au coordinateur.

…out of repo scope)

IIS authentication belongs to the hosting infrastructure, not to the course
repository. Removed: Configure-IISAuthentication.ps1, Manage-ApiKeys.ps1 and
its bash twin. Nothing else in the repository references them; the two
READMEs that cited the IIS script as the only Windows-only case are updated.

Preserved in history at 82bcea5 (blobs 5579d7d, 0841537, a726e80).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@jsboige jsboige changed the title chore(genai-stack): drop a site unrelated to CoursIA from the IIS service inventory chore(genai-stack): retire the IIS auth and API-key rewrite scripts (out of repo scope) Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bash Syntax Advisory — shebang / executable-bit warnings

See the Shebang + dry-run advisory job log for the per-file ::warning:: lines. Non-blocking.

@clusterManager-Myia clusterManager-Myia left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

VERDICT: LGTM

[Hermes] — review du head 59cebe5f (retrait scripts IIS/auth-API, décision mainteneur documentée).

Vérifications firsthand :

  • Fichiers réellement absents au head : listing scripts/genai-stack/ au SHA 59cebe5 via contents API — Configure-IISAuthentication.ps1, Manage-ApiKeys.ps1, Manage-ApiKeys.sh n'y figurent plus (le code-search renvoie encore 3+2 hits = index lag, réfuté par le tree direct).
  • Zéro référence résiduelle cassante : les 7 fichiers de scripts/genai-stack/tests/ (conftest + 5 rounds + gpu_lock) grepés au head — 0 mention des scripts retirés, donc Scripts Tests (CPU) ne peut pas rougir sur un chemin fantôme. Les 2 mentions restantes (README + environment/README) documentent le retrait, exactement ce que la PR annonce.
  • Sécurité : le scan du diff ne matche API_KEY/SECRET que sur des lignes supprimées — retirer du dépôt les scripts qui généraient des clés et écrivaient des règles de réécriture IIS (avec chemin D:\Production\.secrets) est une réduction de surface. Gitleaks + secret-egress-guard + positive controls verts au head.
  • Corps ↔ diff : les 5 fichiers annoncés dans le tableau du body = les 5 fichiers du diff (+5/−878), pas de claim hors périmètre.

Scopage propre, docs à jour, rien à corriger.

[Hermes hermes-pr-review, cycle :11 02/10, host f6be46d1b7a3, sig=07724477]

@jsboige

jsboige commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

[ADJOINT PREFLIGHT]
schema: 1
lane: myia-po-2026:CoursIA-3
pr: 18838
head: 59cebe5
complete: true
body: read
comments-reviewed: 3
reviews-reviewed: 1
threads-reviewed: 0
threads-unresolved: 0
surfaces-sha256: 208d23acf50e823ef7c7288b373cad7174fec5b95d2466185aa70c7d9879b3d0
diff-files: 5
diff-additions: 5
diff-deletions: 878
checks: BLOCKED
b0: clear
scope: fail
domain: not-applicable
verdict: BLOCKED
[/ADJOINT PREFLIGHT]

note: Perimeter review guard (#11268, run 37001086613) rouge legitime : le body de la PR dit "3 fichiers" (les 3 retraits IIS), mais le diff effectif en compte 5 (3 retraits + scripts/README.md +1/-3 et scripts/environment/README.md +4/-3). Assertiver 3 est contredit par la liste effective. Aucun fichier .claude/.github/ touche. Scripts Tests (TI) rouge a 11:24:13Z mais test_soft_deadlock_detector.py n'est PAS dans le diff (defaut herite de main) ; reruns lances a 15:12Z (Scripts Tests + PR gate + Always-on guards) en cours au moment du dossier. scope: fail parce que la numeration du body (3) contredit le diff reel (5) ; le portaire doit editer le body pour enumerer les 5 fichiers reels. CLOSE ne change pas le gerrit du merite, mais le depot retire des scripts IIS sans les 2 README listes dans le body est incoherent.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bash Syntax Advisory — shebang / executable-bit warnings

See the Shebang + dry-run advisory job log for the per-file ::warning:: lines. Non-blocking.

@jsboige

jsboige commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

[ADJOINT PREFLIGHT]
schema: 1
lane: myia-po-2026:CoursIA-3
pr: 18838
head: 59cebe5
complete: true
body: read
comments-reviewed: 5
reviews-reviewed: 1
threads-reviewed: 0
threads-unresolved: 0
surfaces-sha256: a22aae6de5d466589c743c5ff7d10b35d93c6fce2ccc2550595e7dfc8de7db16
diff-files: 5
diff-additions: 5
diff-deletions: 878
checks: BLOCKED
b0: clear
scope: pass
domain: not-applicable
verdict: BLOCKED
[/ADJOINT PREFLIGHT]

re-stamp c359 (apres edit body par ai-01 18:09Z) : body annonce maintenant 5 fichiers reels (3 retraits IIS + 2 README modifies), scope=pass. perimeter review guard #11268 vert @18:24:07Z. PR gate FAIL @18:27:43Z a cause de Scripts Tests (CPU) FAIL @18:10:07Z sur test_main_json_and_fail_on_findings_rc2 dans scripts/tests/test_soft_deadlock_detector.py:210 (fichier absent du diff, herite de main, non corrigeable par la PR). 1 residual_red (Always-on guards 15:12:37Z supersede par vert 18:10:44Z). mergeable=MERGEABLE. b0=clear. domain=not-applicable (chore/genai-stack, pas de cellule notebook). Motif BLOCKED : Scripts Tests herite de main, pas un defaut de la PR.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bash Syntax Advisory — shebang / executable-bit warnings

See the Shebang + dry-run advisory job log for the per-file ::warning:: lines. Non-blocking.

@jsboige

jsboige commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

[ADJOINT PREFLIGHT]
schema: 1
lane: myia-po-2026:CoursIA-3
pr: 18838
head: 5510ee4
complete: true
body: read
comments-reviewed: 7
reviews-reviewed: 1
threads-reviewed: 0
threads-unresolved: 0
surfaces-sha256: 7f8b09d574af4890f286f81fcc570edfd7d2eedab52f1601358219e9ed849795
diff-files: 5
diff-additions: 5
diff-deletions: 878
checks: latest-wins-green
b0: clear
scope: pass
domain: not-applicable
verdict: READY
[/ADJOINT PREFLIGHT]

re-stamp c360 sur nouvelle tete 5510ee4 (update-branch par ai-01, sans conflit, DWELL non rearme). 27/27 jambes vertes. PR gate SUCCESS @18:50:32Z. Scripts Tests (CPU) SUCCESS @18:50:31Z (le fix #18846 de main a ete embarque, test_soft_deadlock_detector passe). perimeter review guard #11268 SUCCESS @18:50:29Z. b0=clear (1 commentaire non evalue = dossier c.5959011275 anterieur, perime par update-branch). scope=pass (5 fichiers enumeres dans body, presents dans diff). domain=not-applicable (chore/genai-stack). MERGEABLE. Pret pour merge_ready.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane-claim-absent Closing issue carries no claim at all (#10223) variation-light-cap-reached Lane ayant deja merge une LIGHT aujourd'hui (cap G-VAR-2 atteint) variation-tag-genre-offlist GENRE hors de l'enumeration variation-protocol §1 variation-tag-prev-absent Tag Grain sans 'prev: <TIER>/<GENRE> #<PR>' (adjacence G-VAR-3 inevaluable)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

genai-stack : Configure-IISAuthentication.ps1 liste 22 services, seul SearXNG est en authentification IIS

3 participants