fix(backend): inject provider credentials from file

This commit is contained in:
2026-07-12 07:53:22 +02:00
parent ee92ef45ab
commit e40a9d9a56
13 changed files with 280 additions and 15 deletions
+7
View File
@@ -17,6 +17,13 @@ docker compose -f compose.yaml -f deploy/compose.production.yaml \
The CA file should contain only the public PEM certificate chain. API-key files should contain
one value with no surrounding quotes.
`THT_MODEL_API_KEY_SECRET_FILE` supplies one generic hosted-model key to the core. The backend
reads it afresh for each Pi child and maps it to the selected provider's native environment name;
the generic path/value is not placed in settings, health output, argv, or logs. Supported hosted
providers include Anthropic, OpenAI, Google/Gemini, DeepSeek, Z.AI, Groq, Mistral, OpenRouter,
xAI, Cerebras, and Cohere. Local Ollama/LM Studio providers require no file. Unknown hosted
providers fail closed until an explicit mapping is added.
## Rotating the initialized local-vector bootstrap password
Replacing `THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE` or changing its contents does **not** rotate