17 lines
1.1 KiB
Markdown
17 lines
1.1 KiB
Markdown
# Model provider credential boundary
|
|
|
|
The backend accepts only an absolute `THT_MODEL_API_KEY_FILE` reference. `PiProcessManager` reads
|
|
and validates it afresh before each hosted-provider spawn, rejects symlinks, non-regular/hard-linked,
|
|
empty, whitespace-containing, oversized, unreadable, or permissively-mode files, and accepts Docker
|
|
0444 secrets only beneath `/run/secrets`. Failures are sanitized and occur before child creation.
|
|
|
|
Provider names are normalized and mapped to Pi-recognized variables. The child environment removes
|
|
the generic path, deprecated `PI_PROVIDER_API_KEY`, and all unselected known provider keys before
|
|
injecting only the selected key. Values never enter argv, settings, health, or diagnostics. Local
|
|
providers remain keyless and unknown hosted providers fail closed.
|
|
|
|
The production Compose overlay mounts `model_api_key` read-only and points the backend at its file;
|
|
the deployment render smoke proves the value is absent from rendered configuration. Entrypoint,
|
|
root README, Pi configuration guide, environment example, and secrets operator guide document the
|
|
new contract and reject the legacy generic value variable.
|