Move the Healthchecks API key out of source code
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 42/100
Research direction
Start by reading internal/status/status.go to trace how the Healthchecks API key is used when fetching cluster status. Define the credential source and missing-credential behavior, then verify that no key remains in source, the committed key is rotated, and CI includes lightweight secret scanning.
Written by the indexing model from the issue text.
Description
Problem
internal/status/status.go sets the Healthchecks API key directly in code when fetching cluster status.
For a public CLI repo, embedding service credentials in source makes key rotation harder and exposes access to anyone with the repository. Even if the current key is read-only or intentionally scoped, it should be treated as leaked once committed.
Suggested fix
- Revoke/rotate the committed Healthchecks API key.
- Load the key from an environment variable, config file, or backend endpoint instead of hardcoding it in the CLI.
- Make the CLI fail with a clear message when status data requires credentials that are not configured.
- Add a lightweight secret scanning check in CI.
Relevant file
internal/status/status.go
- Dominant language
- Go
- Stars
- 0
- Forks
- 1
- Avg merge
- 1d 2h
- Merged PRs (30d)
- 4
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from WATonomous/watcloud-cli
-
[#6] Remove the size argument from docker startPossibly taken @Ixe9230 claimed this 5 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
WATonomous/watcloud-cli#15 · 1 comment · 1 assignee ·
-
[#13.2] slurm run: --batch modePossibly taken @GavinDPinto claimed this 4 days ago. Open
WATonomous/watcloud-cli#31 · 1 assignee ·
-
[#13.1] slurm run: interactive jobsPossibly taken @GavinDPinto claimed this 4 days ago. Open
WATonomous/watcloud-cli#30 · 1 assignee ·
-
good first issue
Difficulty 4/5 1-2 days Newbie friendliness 28/100
WATonomous/watcloud-cli#28 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
WATonomous/watcloud-cli#23 ·
All issues in WATonomous/watcloud-cli
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 73/100
Maintainers usually reply within 1 day
-
bug go
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
genkit-ai/genkit#6761 · 1 comment ·
Maintainers usually reply within 2 days
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 87/100
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
github/github-mcp-server#3475 ·
Maintainers usually reply within 4 days