From 88b6decb318c3e6b10810869bec4857eb340888b Mon Sep 17 00:00:00 2001 From: root Date: Tue, 15 Sep 2026 04:42:31 +0000 Subject: [PATCH] fix: remove false Infisical claim - master key NOT in infrastructure project - Replace Infisical retrieval path with proven docker exec + .env note - State explicitly that master key is NOT in Infisical project=infrastructure - Keep the live-key check and never-trust-a-literal instruction - All other corrections from PR #95 preserved Signed-off-by: Abiba --- litellm-api-keys.prose.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/litellm-api-keys.prose.md b/litellm-api-keys.prose.md index 644b619..9ea71a6 100644 --- a/litellm-api-keys.prose.md +++ b/litellm-api-keys.prose.md @@ -322,10 +322,10 @@ directly call OpenRouter via Python's requests library. Converting would require - Master key: **Retrieval path (do not trust a literal value in this file — the key rotates)**: ```bash - # Read at runtime from the container's environment: + # PRIMARY (proven, runs on CT 116 with no extra tooling): docker exec harness-litellm printenv LITELLM_MASTER_KEY - # Or from Infisical vault (project=infrastructure env=prod) - NOTE: --plain is broken on CLI 0.43.110 (prints nothing): - infisical secrets get LITELLM_MASTER_KEY --project=infrastructure --env=production | awk '$1=="LITELLM_MASTER_KEY"{print $NF}' + # Note: the same value is stored in /opt/inference-harness/.env on CT 116 (verified matching) + # The master key is NOT in the Infisical vault (project=infrastructure env=production does not contain it) # Prove a key is live with a 200 from /key/list on the CT 116 host (the container has no curl): curl -s -H "Authorization: Bearer " http://127.0.0.1:4000/key/list | jq length ```