fix(backend): inject provider credentials from file

This commit is contained in:
2026-07-12 07:53:22 +02:00
parent ee92ef45ab
commit e40a9d9a56
13 changed files with 280 additions and 15 deletions
+5
View File
@@ -11,6 +11,7 @@ services:
THT_DWH_API_KEY_FILE: /run/secrets/dwh_api_key
THT_VEC_API_KEY_FILE: /run/secrets/vector_reader_api_key
THT_VEC_WRITE_API_KEY_FILE: /run/secrets/vector_writer_api_key
THT_MODEL_API_KEY_FILE: /run/secrets/model_api_key
THT_SSL_CA: /run/secrets/thoth_ca.pem
secrets:
- source: dwh_api_key
@@ -21,6 +22,8 @@ services:
target: vector_writer_api_key
- source: thoth_ca
target: thoth_ca.pem
- source: model_api_key
target: model_api_key
secrets:
dwh_api_key:
@@ -31,3 +34,5 @@ secrets:
file: ${THT_VEC_WRITE_API_KEY_SECRET_FILE:?set THT_VEC_WRITE_API_KEY_SECRET_FILE}
thoth_ca:
file: ${THT_CA_SECRET_FILE:?set THT_CA_SECRET_FILE}
model_api_key:
file: ${THT_MODEL_API_KEY_SECRET_FILE:?set THT_MODEL_API_KEY_SECRET_FILE}
+1
View File
@@ -5,6 +5,7 @@
PI_PROVIDER=
PI_MODEL=
PI_THINKING=
THT_MODEL_API_KEY_FILE=/absolute/path/to/model_api_key
MAX_PI_PROCESSES=4
AUTH_MODE=none
+7
View File
@@ -17,6 +17,13 @@ docker compose -f compose.yaml -f deploy/compose.production.yaml \
The CA file should contain only the public PEM certificate chain. API-key files should contain
one value with no surrounding quotes.
`THT_MODEL_API_KEY_SECRET_FILE` supplies one generic hosted-model key to the core. The backend
reads it afresh for each Pi child and maps it to the selected provider's native environment name;
the generic path/value is not placed in settings, health output, argv, or logs. Supported hosted
providers include Anthropic, OpenAI, Google/Gemini, DeepSeek, Z.AI, Groq, Mistral, OpenRouter,
xAI, Cerebras, and Cohere. Local Ollama/LM Studio providers require no file. Unknown hosted
providers fail closed until an explicit mapping is added.
## Rotating the initialized local-vector bootstrap password
Replacing `THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE` or changing its contents does **not** rotate