diff --git a/.github/workflows/diagnose.yml b/.github/workflows/diagnose.yml index aaf7459..feeea8c 100644 --- a/.github/workflows/diagnose.yml +++ b/.github/workflows/diagnose.yml @@ -330,7 +330,8 @@ jobs: sudo journalctl -u ibkr-2fa-bot.service -n 100 --no-pager || true section "container processes" - sudo docker exec "$CONTAINER_NAME" bash -lc 'pgrep -a -f "2fa_bot.py|ibgateway|socat|Xvfb|x11vnc|ibcstart" || true' || true + # Full process arguments may contain license or authentication material. + sudo docker exec "$CONTAINER_NAME" ps -eo pid=,comm= || true section "container listening ports" sudo docker exec "$CONTAINER_NAME" bash -lc 'ss -ltnp 2>/dev/null | grep -E ":(4001|4002|4003|4004|5900)\b" || netstat -ltnp 2>/dev/null | grep -E ":(4001|4002|4003|4004|5900)\b" || true' || true diff --git a/.github/workflows/remote-maintenance.yml b/.github/workflows/remote-maintenance.yml index 741e820..a851411 100644 --- a/.github/workflows/remote-maintenance.yml +++ b/.github/workflows/remote-maintenance.yml @@ -287,7 +287,8 @@ jobs: resolve_ibkr_gateway_unit_names "${container_name}" "${unit_suffix}" sudo docker compose ps sudo systemctl status "${IBKR_GATEWAY_HEALTHCHECK_TIMER}" "${IBKR_GATEWAY_DAILY_RESTART_TIMER}" "${IBKR_2FA_BOT_TIMER}" --no-pager || true - sudo docker exec "${container_name}" pgrep -a -f "2fa_bot.py|ibgateway|socat|Xvfb|x11vnc|ibcstart" 2>/dev/null || true + # Full process arguments may contain license or authentication material. + sudo docker exec "${container_name}" ps -eo pid=,comm= 2>/dev/null || true sudo docker exec "${container_name}" bash -lc 'ss -ltnp 2>/dev/null | grep -E ":(4001|4002|4003|4004|5900)\b" || true' || true sudo docker exec "${container_name}" tail -n 80 /home/ibgateway/2fa.log 2>/dev/null || true EOF diff --git a/README.md b/README.md index 2aaea01..2fdacc9 100644 --- a/README.md +++ b/README.md @@ -31,6 +31,8 @@ It supports the system but does not decide which strategy should be live. Strate Deployment workflows require the repository-level Actions variable `IB_GATEWAY_TARGETS_JSON`. It is a JSON object keyed by a non-sensitive target label (or a list whose entries include `name`). Every target supplies its own GCP project, Workload Identity provider, service account, VM location, and deployment settings. The repository has no default gateway or cloud account. +Setting `maintenance_enabled=false` for a target pauses scheduled redeployment only; it does not disable the Gateway health and 2FA timers already installed on the VM. A scheduled workflow can succeed when every target was skipped, so its result does not verify the Gateway API, login, or account identity. Use the read-only diagnostics and separate account-level evidence; do not enable scheduled redeployment just to obtain a green workflow. + ```json { "gateway-a": { diff --git a/README.zh-CN.md b/README.zh-CN.md index dc1a94a..91c3da4 100644 --- a/README.zh-CN.md +++ b/README.zh-CN.md @@ -31,6 +31,8 @@ IBKRGatewayManager 是 QuantStrategyLab 的IBKR Gateway 运维工具。管理 IB 部署 workflow 必须使用仓库级 Actions variable `IB_GATEWAY_TARGETS_JSON`。它是以非敏感目标标签为 key 的 JSON object(或每项包含 `name` 的 list)。每个目标自行提供 GCP project、Workload Identity provider、service account、VM 位置和部署参数;仓库中没有默认 gateway 或云账号。 +目标的 `maintenance_enabled=false` 仅暂停定时重新部署,不会关闭 VM 上已安装的 Gateway 健康与 2FA 定时器。定时 workflow 在所有目标被跳过时仍可能显示成功;该结果不代表 Gateway API、登录或账户身份已验证。需要运行只读诊断并另行核对账户级证据,不能为了获得绿色状态而重新启用定时部署。 + ```json { "gateway-a": {