Commit Graph

8 Commits

Author SHA1 Message Date
88ef0d6943 Remove hardcoded credentials, harden deployment, optimize OCR
Secrets (S3 keys, PG password, DeerMapper API key) were committed in
config.yaml and .env and remain in git history. This removes them from
the tracked tree and moves all secrets to env injection.

Security:
- config.yaml: drop all credentials, keep only non-secret app tunables
- untrack .env, add .env.example template; .gitignore excludes .env
- main.py: tolerant config lookups + fail-fast validation for missing secrets
- docker-compose: env_file injection, no full-repo bind mount, debug port off
- Dockerfile: bake config into image, run as non-root user

Efficiency:
- OCR: run the second (expensive) tesseract pass only when the first
  is unparsable; identical fallback behavior

Docs:
- README with operation + security notes
- MIGRATION.md runbook: secret rotation, server cutover, decommission,
  git history purge

Note: the leaked secrets are compromised and MUST be rotated; removing
them from the tree is not sufficient. See MIGRATION.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 21:35:04 +02:00
Dom
ddfb281be3 Remove Shiny app and associated Docker configuration 2026-02-09 11:08:13 +00:00
Dom
b35394c569 Add environment configuration and enhance Shiny app with AWS integration 2026-02-08 14:04:42 +00:00
Dom
1e4a7b86b6 Refactor environment variables and remove unused launch configuration 2026-02-07 19:43:14 +00:00
Dom
d71e1699d6 dsaf 2026-02-06 15:33:16 +00:00
Dom
6b39886745 awef 2026-02-06 15:15:48 +00:00
Dom
b9ad76f103 asedf 2026-02-06 14:34:33 +00:00
dom
45d44435af add docker compose 2026-02-06 12:17:15 +01:00