fix: pass vector rotation operator env

This commit is contained in:
2026-08-05 08:12:38 +02:00
parent 09834d5cd4
commit c01202f06c
4 changed files with 139 additions and 10 deletions
+14
View File
@@ -43,6 +43,20 @@ maintenance interface. Run it only with files protected by `0600`, then copy the
password into `THT_VECTOR_BOOTSTRAP_PASSWORD` in the bundle before restarting
`vector-reconcile`/the application. The helper never prints password contents.
The helper has no implicit operator-env default. Pass the same protected env file used for the
deployment explicitly; it must be a readable regular non-symlink file and must not be writable by
group or other users:
```sh
chmod 600 deploy/env/local.env
./scripts/vector-rotate-bootstrap-password.sh \
--env-file "$(pwd)/deploy/env/local.env" \
/secure/thoth/bootstrap-password /secure/thoth/bootstrap-password.next
```
Automation may set the narrowly scoped `THT_VECTOR_OPERATOR_ENV_FILE` instead. An explicit
`--env-file` takes precedence. Missing or unsafe env files are rejected before Compose runs.
Hosted Pi providers must use a single provider key. Compound providers (Bedrock, Azure OpenAI
Responses, Cloudflare Workers AI/Gateway) fail closed until a provider-specific credential
adapter is implemented.