feat(curator): vendor the application backend as the scenario's tracked source

The curator Python backend (package, tests, systemd units, config templates, scripts) now lives under scenarios/curator/backend and is the single source of truth; the live checkout at the workspace path is a runtime copy. Exported from the app repo's tracked tree via git archive (no history, .pi/venv/caches excluded). 149 unit tests pass from the new location.

profile.toml backend is now repo-relative (scenarios/curator/backend); verify-generated.sh resolves a relative backend against REPO_ROOT. verify-no-secrets ASSIGN heuristic now requires value entropy so vendored kwargs like token=extraction_token no longer false-positive. README documents the backend/ layout and the operator-owned app rollout step.
This commit is contained in:
Kai
2026-08-30 18:49:10 -07:00
parent 14c97d88cf
commit 88b06d782f
57 changed files with 14236 additions and 9 deletions
+1
View File
@@ -28,6 +28,7 @@ while IFS= read -r profile; do
name="$(basename "$(dirname "$profile")")"
backend="$(toml_get "$profile" scenario backend)"
[ -n "$backend" ] || continue
case "$backend" in /*) ;; *) backend="$REPO_ROOT/$backend" ;; esac
[ -d "$backend" ] || { warn "$name: backend not found: $backend"; continue; }
while IFS= read -r prompt; do