fix(backend): inject provider credentials from file
This commit is contained in:
@@ -11,6 +11,7 @@ services:
|
||||
THT_DWH_API_KEY_FILE: /run/secrets/dwh_api_key
|
||||
THT_VEC_API_KEY_FILE: /run/secrets/vector_reader_api_key
|
||||
THT_VEC_WRITE_API_KEY_FILE: /run/secrets/vector_writer_api_key
|
||||
THT_MODEL_API_KEY_FILE: /run/secrets/model_api_key
|
||||
THT_SSL_CA: /run/secrets/thoth_ca.pem
|
||||
secrets:
|
||||
- source: dwh_api_key
|
||||
@@ -21,6 +22,8 @@ services:
|
||||
target: vector_writer_api_key
|
||||
- source: thoth_ca
|
||||
target: thoth_ca.pem
|
||||
- source: model_api_key
|
||||
target: model_api_key
|
||||
|
||||
secrets:
|
||||
dwh_api_key:
|
||||
@@ -31,3 +34,5 @@ secrets:
|
||||
file: ${THT_VEC_WRITE_API_KEY_SECRET_FILE:?set THT_VEC_WRITE_API_KEY_SECRET_FILE}
|
||||
thoth_ca:
|
||||
file: ${THT_CA_SECRET_FILE:?set THT_CA_SECRET_FILE}
|
||||
model_api_key:
|
||||
file: ${THT_MODEL_API_KEY_SECRET_FILE:?set THT_MODEL_API_KEY_SECRET_FILE}
|
||||
|
||||
@@ -5,6 +5,7 @@
|
||||
PI_PROVIDER=
|
||||
PI_MODEL=
|
||||
PI_THINKING=
|
||||
THT_MODEL_API_KEY_FILE=/absolute/path/to/model_api_key
|
||||
MAX_PI_PROCESSES=4
|
||||
AUTH_MODE=none
|
||||
|
||||
|
||||
@@ -17,6 +17,13 @@ docker compose -f compose.yaml -f deploy/compose.production.yaml \
|
||||
The CA file should contain only the public PEM certificate chain. API-key files should contain
|
||||
one value with no surrounding quotes.
|
||||
|
||||
`THT_MODEL_API_KEY_SECRET_FILE` supplies one generic hosted-model key to the core. The backend
|
||||
reads it afresh for each Pi child and maps it to the selected provider's native environment name;
|
||||
the generic path/value is not placed in settings, health output, argv, or logs. Supported hosted
|
||||
providers include Anthropic, OpenAI, Google/Gemini, DeepSeek, Z.AI, Groq, Mistral, OpenRouter,
|
||||
xAI, Cerebras, and Cohere. Local Ollama/LM Studio providers require no file. Unknown hosted
|
||||
providers fail closed until an explicit mapping is added.
|
||||
|
||||
## Rotating the initialized local-vector bootstrap password
|
||||
|
||||
Replacing `THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE` or changing its contents does **not** rotate
|
||||
|
||||
Reference in New Issue
Block a user