feat(config): load one validated secret bundle
This commit is contained in:
@@ -2,6 +2,7 @@ import { spawn as nodeSpawn, type ChildProcessWithoutNullStreams } from "node:ch
|
||||
import type { AppConfig } from "../config.js";
|
||||
import { RpcClient } from "../rpc/rpc-client.js";
|
||||
import { buildPiChildEnv } from "./provider-credentials.js";
|
||||
import { secretValue } from "../config/secret-bundle.js";
|
||||
|
||||
export interface PiModel {
|
||||
provider: string;
|
||||
@@ -37,6 +38,7 @@ export function createPiModelLister(cfg: AppConfig, opts: Opts = {}): () => Prom
|
||||
|
||||
const env = buildPiChildEnv({
|
||||
provider: cfg.defaults.provider,
|
||||
credentialValue: secretValue(cfg, "THT_MODEL_API_KEY"),
|
||||
credentialFile: cfg.modelApiKeyFile,
|
||||
});
|
||||
delete env.THT_DATA_ROOT;
|
||||
|
||||
@@ -4,6 +4,7 @@ import { RpcClient } from "../rpc/rpc-client.js";
|
||||
import { SessionBridge } from "../bridge/session-bridge.js";
|
||||
import type { ThtRunner } from "../tht/tht-runner.js";
|
||||
import { buildPiChildEnv, canonicalPiProvider } from "./provider-credentials.js";
|
||||
import { secretValue } from "../config/secret-bundle.js";
|
||||
|
||||
export interface SessionRuntime {
|
||||
rpc: RpcClient;
|
||||
@@ -39,6 +40,7 @@ export class PiProcessManager {
|
||||
): ChildProcessWithoutNullStreams {
|
||||
const env = buildPiChildEnv({
|
||||
provider,
|
||||
credentialValue: secretValue(this.cfg, "THT_MODEL_API_KEY"),
|
||||
credentialFile: this.cfg.modelApiKeyFile,
|
||||
additions: { THT_SESSION: sessionId, THT_AUTHOR: author },
|
||||
});
|
||||
|
||||
@@ -101,11 +101,21 @@ export function buildPiChildEnv(opts: {
|
||||
provider?: string;
|
||||
credentialFile?: string;
|
||||
additions?: NodeJS.ProcessEnv;
|
||||
credentialValue?: string;
|
||||
fsOps?: CredentialFsOps;
|
||||
}): NodeJS.ProcessEnv {
|
||||
const env = { ...(opts.ambient ?? process.env), ...opts.additions };
|
||||
delete env.PI_PROVIDER_API_KEY;
|
||||
delete env.THT_SECRETS_FILE;
|
||||
delete env.THT_MODEL_API_KEY_FILE;
|
||||
delete env.THT_DWH_API_KEY_SECRET_FILE;
|
||||
delete env.THT_VEC_API_KEY_SECRET_FILE;
|
||||
delete env.THT_VEC_WRITE_API_KEY_SECRET_FILE;
|
||||
delete env.THT_CA_SECRET_FILE;
|
||||
delete env.THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE;
|
||||
delete env.THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE;
|
||||
delete env.THT_VECTOR_READER_PASSWORD_SECRET_FILE;
|
||||
delete env.THT_VECTOR_WRITER_PASSWORD_SECRET_FILE;
|
||||
for (const name of PI_0803_CREDENTIAL_ENV_NAMES) delete env[name];
|
||||
const provider = canonicalPiProvider(opts.provider);
|
||||
if (provider && COMPOUND_PROVIDERS.has(provider)) {
|
||||
@@ -116,8 +126,17 @@ export function buildPiChildEnv(opts: {
|
||||
}
|
||||
if (provider && !LOCAL_PROVIDERS.has(provider)) {
|
||||
const envName = PROVIDER_KEY_ENV[provider];
|
||||
if (!envName || !opts.credentialFile) throw new Error("model provider credential is unavailable");
|
||||
env[envName] = readCredential(opts.credentialFile, opts.fsOps ?? realFs);
|
||||
if (!envName || (!opts.credentialFile && opts.credentialValue === undefined)) {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
}
|
||||
if (opts.credentialValue !== undefined) {
|
||||
if (!opts.credentialValue || /\s/.test(opts.credentialValue)) {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
}
|
||||
env[envName] = opts.credentialValue;
|
||||
}
|
||||
else if (opts.credentialFile) env[envName] = readCredential(opts.credentialFile, opts.fsOps ?? realFs);
|
||||
else throw new Error("model provider credential is unavailable");
|
||||
} else if (opts.credentialFile && !provider) {
|
||||
throw new Error("model provider credential is unavailable");
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user