feat(config): load one validated secret bundle

This commit is contained in:
2026-07-12 11:06:19 +02:00
parent b539303002
commit 5fe74612fb
9 changed files with 255 additions and 2 deletions
+2
View File
@@ -2,6 +2,7 @@ import { spawn as nodeSpawn, type ChildProcessWithoutNullStreams } from "node:ch
import type { AppConfig } from "../config.js";
import { RpcClient } from "../rpc/rpc-client.js";
import { buildPiChildEnv } from "./provider-credentials.js";
import { secretValue } from "../config/secret-bundle.js";
export interface PiModel {
provider: string;
@@ -37,6 +38,7 @@ export function createPiModelLister(cfg: AppConfig, opts: Opts = {}): () => Prom
const env = buildPiChildEnv({
provider: cfg.defaults.provider,
credentialValue: secretValue(cfg, "THT_MODEL_API_KEY"),
credentialFile: cfg.modelApiKeyFile,
});
delete env.THT_DATA_ROOT;
+2
View File
@@ -4,6 +4,7 @@ import { RpcClient } from "../rpc/rpc-client.js";
import { SessionBridge } from "../bridge/session-bridge.js";
import type { ThtRunner } from "../tht/tht-runner.js";
import { buildPiChildEnv, canonicalPiProvider } from "./provider-credentials.js";
import { secretValue } from "../config/secret-bundle.js";
export interface SessionRuntime {
rpc: RpcClient;
@@ -39,6 +40,7 @@ export class PiProcessManager {
): ChildProcessWithoutNullStreams {
const env = buildPiChildEnv({
provider,
credentialValue: secretValue(this.cfg, "THT_MODEL_API_KEY"),
credentialFile: this.cfg.modelApiKeyFile,
additions: { THT_SESSION: sessionId, THT_AUTHOR: author },
});
+21 -2
View File
@@ -101,11 +101,21 @@ export function buildPiChildEnv(opts: {
provider?: string;
credentialFile?: string;
additions?: NodeJS.ProcessEnv;
credentialValue?: string;
fsOps?: CredentialFsOps;
}): NodeJS.ProcessEnv {
const env = { ...(opts.ambient ?? process.env), ...opts.additions };
delete env.PI_PROVIDER_API_KEY;
delete env.THT_SECRETS_FILE;
delete env.THT_MODEL_API_KEY_FILE;
delete env.THT_DWH_API_KEY_SECRET_FILE;
delete env.THT_VEC_API_KEY_SECRET_FILE;
delete env.THT_VEC_WRITE_API_KEY_SECRET_FILE;
delete env.THT_CA_SECRET_FILE;
delete env.THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE;
delete env.THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE;
delete env.THT_VECTOR_READER_PASSWORD_SECRET_FILE;
delete env.THT_VECTOR_WRITER_PASSWORD_SECRET_FILE;
for (const name of PI_0803_CREDENTIAL_ENV_NAMES) delete env[name];
const provider = canonicalPiProvider(opts.provider);
if (provider && COMPOUND_PROVIDERS.has(provider)) {
@@ -116,8 +126,17 @@ export function buildPiChildEnv(opts: {
}
if (provider && !LOCAL_PROVIDERS.has(provider)) {
const envName = PROVIDER_KEY_ENV[provider];
if (!envName || !opts.credentialFile) throw new Error("model provider credential is unavailable");
env[envName] = readCredential(opts.credentialFile, opts.fsOps ?? realFs);
if (!envName || (!opts.credentialFile && opts.credentialValue === undefined)) {
throw new Error("model provider credential is unavailable");
}
if (opts.credentialValue !== undefined) {
if (!opts.credentialValue || /\s/.test(opts.credentialValue)) {
throw new Error("model provider credential is unavailable");
}
env[envName] = opts.credentialValue;
}
else if (opts.credentialFile) env[envName] = readCredential(opts.credentialFile, opts.fsOps ?? realFs);
else throw new Error("model provider credential is unavailable");
} else if (opts.credentialFile && !provider) {
throw new Error("model provider credential is unavailable");
}