diff --git a/agent-zero-openrouter-key.prose.md b/agent-zero-openrouter-key.prose.md index 77eb514..8cf9b28 100644 --- a/agent-zero-openrouter-key.prose.md +++ b/agent-zero-openrouter-key.prose.md @@ -54,7 +54,7 @@ description: > ``` 4. **Return status** - - If all checks pass: `{ key_status: "valid", key_prefix: "«vault: agents/production OPENROUTER_API_KEY»", user_id: "user_2rt9lCqcd5d7Vk1t18DHsvWdPTT" }` + - If all checks pass: `{ key_status: "valid", key_prefix: "sk-or-v1-synthetic...", user_id: "user_2rt9lCqcd5d7Vk1t18DHsvWdPTT" }` - If OpenRouter returns 401: `{ key_status: "invalid", detail: "User not found" }` - If vault secret is missing: `{ vault_synced: false }` @@ -90,7 +90,7 @@ description: > | Field | Value | |-------|-------| | **Key Prefix** | `«vault: agents/production OPENROUTER_API_KEY»` | -| **Full Key** | `«redacted:«vault: agents/production OPENROUTER_API_KEY»»` (in vault + /a0/usr/.env) | +| **Full Key** | `«vault: agents/production OPENROUTER_API_KEY»` (in vault + /a0/usr/.env) | | **OpenRouter User** | `user_2rt9lCqcd5d7Vk1t18DHsvWdPTT` | | **Free Tier** | No | | **Monthly Usage** | 0 (as of 2026-09-01) | diff --git a/hermes-key-enforcement.prose.md b/hermes-key-enforcement.prose.md index d2320d0..7c767a2 100644 --- a/hermes-key-enforcement.prose.md +++ b/hermes-key-enforcement.prose.md @@ -101,7 +101,7 @@ auxiliary: fallback_providers: - provider: deepseek base_url: https://api.deepseek.com - api_key: «vault: external/production LITELLM_API_KEY» # ← hardcoded OK (external) + api_key: sk-synthetic-external-example # ← hardcoded OK (external, synthetic example) api_key_env: DEEPSEEK_API_KEY # ← also OK if set in environment (vault or /etc/environment) ``` @@ -182,7 +182,7 @@ grep -rn 'litellm/v1/responses' /root/.hermes/config.yaml # 2. Check systemd drop-ins for master key leaks (2026-07-05: Tanko had this) grep -rn 'LITELLM_API_KEY' /root/.config/systemd/user/ 2>/dev/null -grep -rn 'LITELLM_API_KEY=sk-litellm-7f96080d' /root/.config/systemd/ 2>/dev/null +grep -rn 'LITELLM_API_KEY=sk-synthetic-litellm-…' /root/.config/systemd/ 2>/dev/null # 3. Verify running process env matches dedicated key cat /proc/$(cat /home/jerome/.hermes/gateway.pid | python3 -c "import sys,json; print(json.load(sys.stdin)['pid'])")/environ \ diff --git a/litellm-api-keys.prose.md b/litellm-api-keys.prose.md index 0f7fb22..9c35f0f 100644 --- a/litellm-api-keys.prose.md +++ b/litellm-api-keys.prose.md @@ -191,7 +191,7 @@ through its agent wrapper. ### Tanko migration (COMPLETED 2026-07-17) Tanko was the last agent migrated from hardcoded keys to vault wrapper. -Previously: key hardcoded in `/home/jerome/.hermes/config.yaml` (`api_key: sk-CggiHWlamQy…`) +Previously: key hardcoded in `/home/jerome/.hermes/config.yaml` (`api_key: sk-synthetic-tanko-example…`) and `zulip-env.conf` systemd drop-in. Now: user-scope systemd service with drop-in `50-vault-wrapper.conf`, `infisical-gateway.sh` wrapper with while-true loop, token at `~/.infisical-token`, `.env` fallback at `~/.hermes/.env`. Keys injected live from vault. @@ -277,7 +277,7 @@ UI bootstrap, model selection) is built around OpenRouter's native authenticatio (unlike fleet agents which require vault injection) **Current Key (2026-09-01):** -- **Prefix**: `«vault: agents/production OPENROUTER_API_KEY»`…` +- **Prefix**: `«vault: agents/production OPENROUTER_API_KEY»` - **User**: `user_2rt9lCqcd5d7Vk1t18DHsvWdPTT` - **Plan**: Paid (not free tier) - **Usage**: 0 (as of 2026-09-01) diff --git a/scripts/agent-health-check.py b/scripts/agent-health-check.py index 62b1f06..8f8502a 100755 --- a/scripts/agent-health-check.py +++ b/scripts/agent-health-check.py @@ -129,6 +129,8 @@ if not INFISICAL_TOKEN: try: with open(_token_path) as _f: INFISICAL_TOKEN = _f.read().strip() + except (OSError, UnicodeDecodeError): + pass INFISICAL_API_URL = os.environ.get("INFISICAL_API_URL", "https://vault.sysloggh.net") # ── Helpers ──────────────────────────────────────────────────────────