fix: correct key-lifecycle contracts to match measured reality
- hermes-key-enforcement.prose.md: - State that expiry must be set EXPLICITLY at creation with duration - Record that config default is NOT honoured by LiteLLM 1.99.1 - Describe daily audit as AUDIT-ONLY (reports non-expiring and soon-to-expire) - State that renewal is NOT implemented - Document exclusions: abiba-pi and all crewmate keys stay WITHOUT expiry - koby is report-only - litellm-api-keys.prose.md: - Replace literal master key with retrieval path (docker exec + infisical) - State that literal values must never be trusted again (key rotates) - Add live-key check (200 from /key/list) Signed-off-by: Abiba
This commit is contained in:
@@ -320,7 +320,15 @@ directly call OpenRouter via Python's requests library. Converting would require
|
||||
|
||||
## LiteLLM Master Key (use sparingly — agents should NOT use it directly)
|
||||
|
||||
- Master key: `sk-litellm-7f96080dd99b15c36bd4b333b58a6796` (in /opt/inference-harness/.env on CT116, Infisical project=infrastructure env=production secret=LITELLM_MASTER_KEY)
|
||||
- Master key: **Retrieval path (do not trust a literal value in this file — the key rotates)**:
|
||||
```bash
|
||||
# Read at runtime from the container's environment:
|
||||
docker exec harness-litellm printenv LITELLM_MASTER_KEY
|
||||
# Or from Infisical vault (project=infrastructure env=prod):
|
||||
infisical secrets get LITELLM_MASTER_KEY --project=infrastructure --env=production --plain
|
||||
# Prove a key is live with a 200 from /key/list on the CT 116 host (the container has no curl):
|
||||
curl -s -H "Authorization: Bearer <key>" http://192.168.68.116/litellm/key/list | jq length
|
||||
```
|
||||
- Used for /key/generate, /key/delete, /key/list (GET), DB queries
|
||||
- **Known violation (RESOLVED 2026-07-16):** Abiba's LITELLM_API_KEY was previously the master key.
|
||||
It is now a dedicated agent key `sk-sxbphLvk1OU…` (vault secret `ABIBA_LITELLM_API_KEY`, alias `abiba-pi`).
|
||||
|
||||
Reference in New Issue
Block a user