docs: update key enforcement — all agents named keys, systemd fix, CI pipeline
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Failing after 3s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Has been skipped

- All 4 Hermes agents now have dedicated named LiteLLM keys (tanko, mumuni, koby, koonimo)
- Documented systemd drop-in pattern fix (litellm-key.conf)
- Added one-step rotation procedure
- Added CI pipeline and branch protection documentation
- Removed old mumuni keys, generated fresh keys for koby/koonimo
This commit is contained in:
root
2026-07-04 23:28:59 +00:00
parent b3ab3a6850
commit 889f4e4dd1
+45 -8
View File
@@ -118,14 +118,36 @@ litellm_settings:
## Verified Agents (2026-07-04 final)
| Agent | CT | Status | api_key_env entries | Hardcoded harness | Last Verified |
|-------|-----|--------|---------------------|-------------------|---------------|
| Tanko | 112 | ✅ Compliant (key: tanko) | 4 | 0 | 22:45 EDT |
| Mumuni | 114 | ✅ Compliant | 8 | 0 | 19:14 EDT |
| Koby | 111 | ✅ Compliant | 14 | 0 | 19:14 EDT |
| Koonimo | 113 | ✅ Compliant | 7 | 0 | 19:14 EDT |
| Abiba | 100 | ✅ N/A (pi native) | — | — | 19:14 EDT |
| Kagenz0 | 105 | ❌ DOWN | — | — | 19:14 EDT |
| Agent | CT | Status | LiteLLM Alias | Key Type | Systemd Source | Last Verified |
|-------|-----|--------|---------------|----------|----------------|---------------|
| Tanko | 112 | ✅ Compliant | `tanko` | Dedicated | `/etc/environment` only | 23:00 EDT |
| Mumuni | 114 | ✅ Compliant | `mumuni` | Dedicated | `/etc/environment` only | 23:00 EDT |
| Koby | 111 | ✅ Compliant | `koby` | Dedicated | User service + drop-in | 23:00 EDT |
| Koonimo | 113 | ✅ Compliant | `koonimo` | Dedicated | System service + drop-in | 23:00 EDT |
| Abiba | 100 | ✅ N/A (pi native) | — | — | — | 23:00 EDT |
| Kagenz0 | 105 | ❌ DOWN | — | — | — | 19:14 EDT |
### Systemd Service Pattern (2026-07-04 fix)
All Hermes agents use systemd to manage their gateway. Two issues were fixed:
1. **Drop-in override**`/etc/systemd/system/hermes-gateway.service.d/litellm-key.conf` (or user equivalent) had hardcoded `LITELLM_API_KEY` that bypassed `/etc/environment`.
2. **Missing EnvironmentFile** — Services did not source `/etc/environment`.
**Correct pattern:**
```ini
# In service file:
EnvironmentFile=/etc/environment
# Drop-in only for overrides, NOT primary key storage.
# If a drop-in exists, it must match /etc/environment.
```
**Rotation procedure** (one step with this standard):
1. Generate new key in LiteLLM: `curl /key/generate` with agent alias
2. Update `/etc/environment`: `sed -i 's/LITELLM_API_KEY=.*/LITELLM_API_KEY=sk-NEW/' /etc/environment`
3. Update drop-in (if exists): same sed on `litellm-key.conf`
4. Restart: `systemctl [--user] restart hermes-gateway`
## Violation Response
@@ -141,3 +163,18 @@ litellm_settings:
- `hermes-config-template.prose.md` — full configuration template
- `litellm-health.prose.md` — LiteLLM stack health verification
- `zulip-platform-verification.prose.md` — cross-platform agent verification
- `litellm-api-keys.prose.md` — API key creation, rotation, and verification
## CI Pipeline (2026-07-04)
All contract changes must pass the PR Pipeline before merge:
```
auth → validate → lint → ai-review → gate
```
- **Trigger**: push to master (abiba-bot only) or pull request
- **Branch protection**: Only `abiba-bot` can push directly to master. All other users must use PRs.
- **Status check**: `PR Pipeline — Authorize → Validate → Review → Merge` required before merge
- **Runner**: `runner-ct110` (Gitea Actions v0.6.1) on CT 110
- **Config**: `.gitea/workflows/pr-pipeline.yaml`