fix: remove false Infisical claim - master key NOT in infrastructure project
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 7s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 3s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s

- Replace Infisical retrieval path with proven docker exec + .env note
- State explicitly that master key is NOT in Infisical project=infrastructure
- Keep the live-key check and never-trust-a-literal instruction
- All other corrections from PR #95 preserved

Signed-off-by: Abiba
This commit is contained in:
root
2026-09-15 04:42:31 +00:00
parent 7bf9f78fc6
commit 88b6decb31
+3 -3
View File
@@ -322,10 +322,10 @@ directly call OpenRouter via Python's requests library. Converting would require
- Master key: **Retrieval path (do not trust a literal value in this file — the key rotates)**: - Master key: **Retrieval path (do not trust a literal value in this file — the key rotates)**:
```bash ```bash
# Read at runtime from the container's environment: # PRIMARY (proven, runs on CT 116 with no extra tooling):
docker exec harness-litellm printenv LITELLM_MASTER_KEY docker exec harness-litellm printenv LITELLM_MASTER_KEY
# Or from Infisical vault (project=infrastructure env=prod) - NOTE: --plain is broken on CLI 0.43.110 (prints nothing): # Note: the same value is stored in /opt/inference-harness/.env on CT 116 (verified matching)
infisical secrets get LITELLM_MASTER_KEY --project=infrastructure --env=production | awk '$1=="LITELLM_MASTER_KEY"{print $NF}' # The master key is NOT in the Infisical vault (project=infrastructure env=production does not contain it)
# Prove a key is live with a 200 from /key/list on the CT 116 host (the container has no curl): # Prove a key is live with a 200 from /key/list on the CT 116 host (the container has no curl):
curl -s -H "Authorization: Bearer <key>" http://127.0.0.1:4000/key/list | jq length curl -s -H "Authorization: Bearer <key>" http://127.0.0.1:4000/key/list | jq length
``` ```