netanalyzer/.env.example
Joseph McQueen b3c37bd7df feat: st command suite, Webex phone + Atlas AV integrations, dockerized remote agent
Rebrand NetAnalyzer -> StoreHealthAnalyzer and consolidate the store
reporting surface into a single `st [number]` command with focused
sub-modes.

Commands
- st [number]                - general info (SIW + brands + Meraki net link)
- st [number] network        - switches, APs, store server
- st [number] pos            - registers, payment terminals, customer display
- st [number] ios            - MDM-tracked iOS hardware
- st [number] phone          - wired 78xx + DECT basestations/handsets with
                               registration state, extensions and main DID
- st [number] av             - Atlas AMPs + MDM-tracked Apple TVs, video
                               walls, music players, LED displays
- Removed `analyze` in favor of the unified `st` surface

Integrations
- integrations/webex: Service App OAuth with rotating refresh tokens,
  seed + cleanup scripts, tokens/ storage (git-ignored)
- integrations/atlas: Xyte client + cached device discovery keyed on
  zero-padded 6-digit store numbers, cold-cache failure -> unavailable
  banner instead of a misleading empty result
- services/webexPhone, services/webexService, services/avService: shape
  raw upstream data into the report layer's contract
- utils/merakiMatcher: FQDN hostname extraction so payment terminals
  match Meraki descriptions; case-insensitive lookup
- utils/chunkReport: split long markdown replies at 7000-char boundaries

Reliability / ops
- server.js: awaited framework.stop() + 8s hard-kill timer so nodemon /
  Docker restarts don't leak WDM device registrations ("excessive device
  registrations")
- nodemon.json: SIGINT so the graceful path always runs
- scripts/cleanupWebexDevices.js: one-shot WDM cleanup utility
- Group-space routing: hears() regexes tolerate the leading @BotName
  prefix Webex prepends to mentions
- Replaced HTML-unsafe <number> placeholders with [number] in all help
  strings

Remote agent containerization
- docker/remote-agent/: multi-stage node:22-alpine image, non-root user,
  tini for signal handling, minimal deps (ws/axios/dotenv)
- docker/remote-agent/package.sh: docker buildx build defaulting to
  linux/amd64 (with override), saves image + assembles deploy/ + writes
  SHA256 + zips for offline transfer
- docker/remote-agent/deploy/: runtime docker-compose.yml, install.sh
  with platform sanity check, remote-host README
- .dockerignore + .gitignore updates for build artifacts and dist bundles
- npm run agent:package convenience script

Cleanup
- Dropped storeHealth.js / HealthReport.js and their tests/mocks in favor
  of the shared storeDetail pipeline
- Store model handles null SIW records gracefully; toSummary always
  ends with a newline so the Meraki link sits on its own line

Tests
- 144 tests across 14 suites passing; new coverage for atlasClient,
  atlasDevices, avService, avCategory classification, webexPhone,
  webexServiceAppAuth, storeDetail integration, siw, chunkReport and
  the updated meraki matcher

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-06 09:54:41 -04:00

54 lines
2.3 KiB
Text

# =============================================================================
# StoreHealthAnalyzer Environment Configuration
# Copy this file to .env and fill in your actual values.
# NEVER commit .env — it is gitignored.
# =============================================================================
# --- Logging ---
# debug | info | warn | error (default: info)
LOG_LEVEL=info
# --- Webex Bot (required for bot functionality) ---
WEBEX_ACCESS_TOKEN=your_webex_bot_access_token_here
BOT_NAME=StoreHealthAnalyzer
# --- Meraki (required for network device discovery and client status) ---
MERAKI_API_KEY=your_meraki_api_key_here
MERAKI_ORG_ID=your_meraki_organization_id_here
# --- WebSocket Remote Agent ---
WS_PORT=8080
# Token used to authenticate the remoteAgent.js when connecting to this server
WS_TOKEN=generate_a_strong_random_token_here
# For the remote agent process (remoteAgent.js), point to the main server
WS_URL=ws://localhost:8080?token=generate_a_strong_random_token_here
# --- SIW / Store Information Warehouse (proxied via remote agent) ---
SIW_BASE_URL=https://your-siw-api.example.com/api
SIW_USERNAME=your_siw_username
SIW_PASSWORD=your_siw_password
# --- Workspace ONE (MDM / AirWatch) ---
WS1_BASE_URL=https://your-tenant.awmdm.com
WS1_TOKEN_URL=https://your-tenant.awmdm.com/api/mdm/token
WS1_CLIENT_ID=your_ws1_client_id
WS1_CLIENT_SECRET=your_ws1_client_secret
WS1_TENANT_CODE=your_ws1_tenant_code
# --- Webex Service App (required for `st [number] phone` only) ---
# Client ID/secret from the Service App registration in the Webex Developer Portal.
WEBEX_CLIENT_ID=your_webex_service_app_client_id
WEBEX_CLIENT_SECRET=your_webex_service_app_client_secret
# Path to the rotating tokens JSON. Created/refreshed by `npm run webex:seed`.
# Defaults to ./tokens/webex-service-tokens.json (resolved to absolute at runtime).
WEBEX_TOKENS_PATH=./tokens/webex-service-tokens.json
# --- Atlas / Xyte (required for `st [number] av` only) ---
# Long-lived API key issued by the Atlas (hub.xyte.io) admin console. Sent
# verbatim as the Authorization header (no rotation, no "Bearer" prefix).
# Missing key surfaces as an inline banner in AV mode; MDM-tracked AV devices
# (Apple TVs, video walls, music, LED) still render.
ATLAS_AUTH_KEY=your_atlas_api_key
# Optional override; defaults to https://hub.xyte.io/core/v1 if unset.
ATLAS_BASE_URL=https://hub.xyte.io/core/v1