docs: update key enforcement — all agents named keys, systemd fix, CI pipeline
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Failing after 3s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Has been skipped
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Failing after 3s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Has been skipped
- All 4 Hermes agents now have dedicated named LiteLLM keys (tanko, mumuni, koby, koonimo) - Documented systemd drop-in pattern fix (litellm-key.conf) - Added one-step rotation procedure - Added CI pipeline and branch protection documentation - Removed old mumuni keys, generated fresh keys for koby/koonimo
This commit is contained in:
@@ -118,14 +118,36 @@ litellm_settings:
|
||||
|
||||
## Verified Agents (2026-07-04 final)
|
||||
|
||||
| Agent | CT | Status | api_key_env entries | Hardcoded harness | Last Verified |
|
||||
|-------|-----|--------|---------------------|-------------------|---------------|
|
||||
| Tanko | 112 | ✅ Compliant (key: tanko) | 4 | 0 | 22:45 EDT |
|
||||
| Mumuni | 114 | ✅ Compliant | 8 | 0 | 19:14 EDT |
|
||||
| Koby | 111 | ✅ Compliant | 14 | 0 | 19:14 EDT |
|
||||
| Koonimo | 113 | ✅ Compliant | 7 | 0 | 19:14 EDT |
|
||||
| Abiba | 100 | ✅ N/A (pi native) | — | — | 19:14 EDT |
|
||||
| Kagenz0 | 105 | ❌ DOWN | — | — | 19:14 EDT |
|
||||
| Agent | CT | Status | LiteLLM Alias | Key Type | Systemd Source | Last Verified |
|
||||
|-------|-----|--------|---------------|----------|----------------|---------------|
|
||||
| Tanko | 112 | ✅ Compliant | `tanko` | Dedicated | `/etc/environment` only | 23:00 EDT |
|
||||
| Mumuni | 114 | ✅ Compliant | `mumuni` | Dedicated | `/etc/environment` only | 23:00 EDT |
|
||||
| Koby | 111 | ✅ Compliant | `koby` | Dedicated | User service + drop-in | 23:00 EDT |
|
||||
| Koonimo | 113 | ✅ Compliant | `koonimo` | Dedicated | System service + drop-in | 23:00 EDT |
|
||||
| Abiba | 100 | ✅ N/A (pi native) | — | — | — | 23:00 EDT |
|
||||
| Kagenz0 | 105 | ❌ DOWN | — | — | — | 19:14 EDT |
|
||||
|
||||
### Systemd Service Pattern (2026-07-04 fix)
|
||||
|
||||
All Hermes agents use systemd to manage their gateway. Two issues were fixed:
|
||||
|
||||
1. **Drop-in override** — `/etc/systemd/system/hermes-gateway.service.d/litellm-key.conf` (or user equivalent) had hardcoded `LITELLM_API_KEY` that bypassed `/etc/environment`.
|
||||
2. **Missing EnvironmentFile** — Services did not source `/etc/environment`.
|
||||
|
||||
**Correct pattern:**
|
||||
```ini
|
||||
# In service file:
|
||||
EnvironmentFile=/etc/environment
|
||||
|
||||
# Drop-in only for overrides, NOT primary key storage.
|
||||
# If a drop-in exists, it must match /etc/environment.
|
||||
```
|
||||
|
||||
**Rotation procedure** (one step with this standard):
|
||||
1. Generate new key in LiteLLM: `curl /key/generate` with agent alias
|
||||
2. Update `/etc/environment`: `sed -i 's/LITELLM_API_KEY=.*/LITELLM_API_KEY=sk-NEW/' /etc/environment`
|
||||
3. Update drop-in (if exists): same sed on `litellm-key.conf`
|
||||
4. Restart: `systemctl [--user] restart hermes-gateway`
|
||||
|
||||
## Violation Response
|
||||
|
||||
@@ -141,3 +163,18 @@ litellm_settings:
|
||||
- `hermes-config-template.prose.md` — full configuration template
|
||||
- `litellm-health.prose.md` — LiteLLM stack health verification
|
||||
- `zulip-platform-verification.prose.md` — cross-platform agent verification
|
||||
- `litellm-api-keys.prose.md` — API key creation, rotation, and verification
|
||||
|
||||
## CI Pipeline (2026-07-04)
|
||||
|
||||
All contract changes must pass the PR Pipeline before merge:
|
||||
|
||||
```
|
||||
auth → validate → lint → ai-review → gate
|
||||
```
|
||||
|
||||
- **Trigger**: push to master (abiba-bot only) or pull request
|
||||
- **Branch protection**: Only `abiba-bot` can push directly to master. All other users must use PRs.
|
||||
- **Status check**: `PR Pipeline — Authorize → Validate → Review → Merge` required before merge
|
||||
- **Runner**: `runner-ct110` (Gitea Actions v0.6.1) on CT 110
|
||||
- **Config**: `.gitea/workflows/pr-pipeline.yaml`
|
||||
|
||||
Reference in New Issue
Block a user