feat(auth): integrate authentication with installation lifecycle
This commit is contained in:
@@ -9,8 +9,10 @@ chmod 600 deploy/secrets/thothii.secrets
|
||||
```
|
||||
|
||||
The file uses strict `KEY=VALUE` lines (comments and blank lines are allowed). The supported
|
||||
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, and `THT_SSL_CA`. Values must be
|
||||
non-empty and contain no whitespace. Do not put secrets
|
||||
keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_CA`, `THT_SSL_CA`,
|
||||
`THT_OIDC_CLIENT_SECRET`, and `THT_AUTHENTIK_API_TOKEN`. The two authentication keys are fixed
|
||||
empty entries for local authentication and must be populated only in a protected OIDC installation.
|
||||
Other configured values must be non-empty and contain no whitespace. Do not put secrets
|
||||
in the root `.env`, workspace YAML, URLs, logs, or rendered Compose output.
|
||||
|
||||
Do not add vector or embedding endpoint credentials to the bundle. Active operator manuals use
|
||||
|
||||
Reference in New Issue
Block a user