fix: remove false Infisical claim - master key NOT in infrastructure project
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 7s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 3s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 7s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 3s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
- Replace Infisical retrieval path with proven docker exec + .env note - State explicitly that master key is NOT in Infisical project=infrastructure - Keep the live-key check and never-trust-a-literal instruction - All other corrections from PR #95 preserved Signed-off-by: Abiba
This commit is contained in:
@@ -322,10 +322,10 @@ directly call OpenRouter via Python's requests library. Converting would require
|
|||||||
|
|
||||||
- Master key: **Retrieval path (do not trust a literal value in this file — the key rotates)**:
|
- Master key: **Retrieval path (do not trust a literal value in this file — the key rotates)**:
|
||||||
```bash
|
```bash
|
||||||
# Read at runtime from the container's environment:
|
# PRIMARY (proven, runs on CT 116 with no extra tooling):
|
||||||
docker exec harness-litellm printenv LITELLM_MASTER_KEY
|
docker exec harness-litellm printenv LITELLM_MASTER_KEY
|
||||||
# Or from Infisical vault (project=infrastructure env=prod) - NOTE: --plain is broken on CLI 0.43.110 (prints nothing):
|
# Note: the same value is stored in /opt/inference-harness/.env on CT 116 (verified matching)
|
||||||
infisical secrets get LITELLM_MASTER_KEY --project=infrastructure --env=production | awk '$1=="LITELLM_MASTER_KEY"{print $NF}'
|
# The master key is NOT in the Infisical vault (project=infrastructure env=production does not contain it)
|
||||||
# Prove a key is live with a 200 from /key/list on the CT 116 host (the container has no curl):
|
# Prove a key is live with a 200 from /key/list on the CT 116 host (the container has no curl):
|
||||||
curl -s -H "Authorization: Bearer <key>" http://127.0.0.1:4000/key/list | jq length
|
curl -s -H "Authorization: Bearer <key>" http://127.0.0.1:4000/key/list | jq length
|
||||||
```
|
```
|
||||||
|
|||||||
Reference in New Issue
Block a user