feat: unify installation model catalog
This commit is contained in:
@@ -10,8 +10,9 @@ chmod 600 deploy/secrets/thothii.secrets
|
||||
|
||||
The file uses strict `KEY=VALUE` lines (comments and blank lines are allowed). The supported
|
||||
installation keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, `THT_SSL_CA`,
|
||||
`THT_OIDC_CLIENT_SECRET`, and `THT_AUTHENTIK_API_TOKEN`. Metadata-generation models may reference
|
||||
exactly one of `THT_METADATA_API_KEY`, `ANTHROPIC_API_KEY`, `AZURE_API_KEY`, `GEMINI_API_KEY`,
|
||||
`THT_OIDC_CLIENT_SECRET`, and `THT_AUTHENTIK_API_TOKEN`. Installation Model Catalog providers may
|
||||
reference exactly one of `THT_MODEL_API_KEY`, `THT_METADATA_API_KEY`, `ANTHROPIC_API_KEY`,
|
||||
`AZURE_API_KEY`, `GEMINI_API_KEY`,
|
||||
`DEEPSEEK_API_KEY`, `OPENAI_API_KEY`, `OPENROUTER_API_KEY`, or `ZAI_API_KEY` through their
|
||||
descriptor `apiKeyEnv`. An entry for an explicitly configured endpoint that accepts unauthenticated
|
||||
requests may omit `apiKeyEnv`; hosted/default endpoints must always reference a key.
|
||||
@@ -23,10 +24,10 @@ installation. Other configured values must be non-empty and contain no
|
||||
whitespace. Do not put secrets in the root `.env`, installation YAML, workspace YAML, URLs, logs,
|
||||
or rendered Compose output.
|
||||
|
||||
`THT_MODEL_API_KEY` remains the generic Pi child credential. Metadata generation is a separate
|
||||
backend-owned runtime and reads only the key named by its own `metadataGeneration.models[].apiKeyEnv`
|
||||
(when present);
|
||||
it does not read Pi settings, `PI_AUTH_FILE`, or workspace `llm_policy`.
|
||||
Session and metadata-generation runtimes read only the provider key named by
|
||||
`modelCatalog.providers.<provider>.authentication.apiKeyEnv`. They share the declaration and
|
||||
credential reference, not their execution lifecycle. Pi-owned authentication remains available only
|
||||
to session-only built-in providers through `authentication.mode: pi_auth`.
|
||||
|
||||
Do not add vector or embedding endpoint credentials to the bundle. Active operator manuals use
|
||||
internal Qdrant and Ollama services, so vector/embedding runtime endpoint secrets are not part of
|
||||
@@ -56,7 +57,7 @@ and only then deleting the old files. The old variables remain a compatibility p
|
||||
upgrades, but the documented and tested default is an absolute `THT_SECRETS_FILE` path to the
|
||||
protected bundle.
|
||||
|
||||
Hosted Pi providers must use a single model key through `THT_MODEL_API_KEY`. Compound providers
|
||||
Hosted providers must use one explicitly named catalog key. Compound providers
|
||||
(Bedrock, Azure OpenAI Responses, Cloudflare Workers AI/Gateway) fail closed until a
|
||||
provider-specific credential adapter is implemented.
|
||||
|
||||
|
||||
@@ -2,14 +2,13 @@
|
||||
# Values are read as literal strings (no shell expansion or command substitution).
|
||||
# Leave unused keys out of the file.
|
||||
|
||||
# Hosted model provider (single-key providers only).
|
||||
# THT_MODEL_API_KEY=replace-me
|
||||
|
||||
# Description Generation only. The selected name must match apiKeyEnv in metadataGeneration.
|
||||
# Allowed names: THT_METADATA_API_KEY, ANTHROPIC_API_KEY, AZURE_API_KEY, GEMINI_API_KEY,
|
||||
# Hosted catalog provider (single-key providers only). The selected name must match
|
||||
# modelCatalog.providers.<provider>.authentication.apiKeyEnv.
|
||||
# Allowed names include THT_MODEL_API_KEY, THT_METADATA_API_KEY, ANTHROPIC_API_KEY,
|
||||
# AZURE_API_KEY, GEMINI_API_KEY,
|
||||
# DEEPSEEK_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, or ZAI_API_KEY.
|
||||
# OPENAI_API_KEY=replace-me
|
||||
# A model with an explicit unauthenticated endpoint omits apiKeyEnv and needs no bundle entry.
|
||||
# A provider with an explicit keyless endpoint uses authentication.mode: none.
|
||||
|
||||
# External DWH adapter.
|
||||
# THT_DWH_API_KEY=replace-me
|
||||
|
||||
Reference in New Issue
Block a user