fix(backend): inject provider credentials from file
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
# Model provider credential boundary
|
||||
|
||||
The backend accepts only an absolute `THT_MODEL_API_KEY_FILE` reference. `PiProcessManager` reads
|
||||
and validates it afresh before each hosted-provider spawn, rejects symlinks, non-regular/hard-linked,
|
||||
empty, whitespace-containing, oversized, unreadable, or permissively-mode files, and accepts Docker
|
||||
0444 secrets only beneath `/run/secrets`. Failures are sanitized and occur before child creation.
|
||||
|
||||
Provider names are normalized and mapped to Pi-recognized variables. The child environment removes
|
||||
the generic path, deprecated `PI_PROVIDER_API_KEY`, and all unselected known provider keys before
|
||||
injecting only the selected key. Values never enter argv, settings, health, or diagnostics. Local
|
||||
providers remain keyless and unknown hosted providers fail closed.
|
||||
|
||||
The production Compose overlay mounts `model_api_key` read-only and points the backend at its file;
|
||||
the deployment render smoke proves the value is absent from rendered configuration. Entrypoint,
|
||||
root README, Pi configuration guide, environment example, and secrets operator guide document the
|
||||
new contract and reject the legacy generic value variable.
|
||||
Reference in New Issue
Block a user