Follow-ups from the credential purge (#112): refusal diagnostics, Key Prefix labels, truncated prefixes in rotation history #113
Open
opened 2026-09-17 07:15:39 +00:00 by abiba-bot
·
0 comments
No Branch/Tag Specified
master
fix/agent-health-root-hardcoding-20260928
fix/contract-alignment-f2-hermes-baseline-20260928
fix/contract-alignment-f3-tanko-hybrid-20260928
fix/contract-alignment-f1-swap-gpu-user-20260928
fix/agent-health-gpu-user-20260928
fix/agent-health-tanko-pve-mapping-20260928
fix/audit-hermes-fallback-list-20260927
fix/hermes-aux-model-policy-20260927
fix/memory-fixer-duplicate-detection-20260926
feat/search-agent-consumption-20260926
fix/daily-digest-zulip-delivery-20260926
fix/health-log-freshness-watchdog-20260926
fm/commit-time-secret-guard-20260917
decisions-2026-08-03-rebased
fix/daily-health-digest-remove-vestigial-zulip-20260921
fix/daily-health-digest-degraded-credentials-20260921
feat/align-litellm-contracts-cloud-20260920
fm/kagentz-a2a-outage-masked-as-expected-20260919
fix/litellm-health-busy-vs-down-20260919
fix/rule5-canonical-baseurl-20260919
fix/litellm-health-retry-timeout-20260919
fix/infra-monitoring-probe-ports-20260919
fix/pbs-gc-liveness-signal-20260919
fix/infra-monitoring-probe-targets-drift-20260917
fix/infra-mcp-per-key-grants-20260918
fix/mcp-rule15-wording-contradiction-20260918
docs/pbs-gc-schedule-20260918
fm/hermes-config-mcp-url-validation
fix/monitor-creds-to-env-master-20260910
fix/agent-health-mandatory-report-legs-20260917
fix/litellm-key-count-self-describing-20260916
fix/tanko-plaintext-key-in-config-backup-20260916
fix/agent-health-check-contract-20260916
fix/host-disk-band-state-file-20260916
fix/host-filesystem-thresholds-20260915
fix/contract-corrections-20260915
cleanup/remove-scot-deliverable-20260912
fm/ci-paths-filter-skips-deliverables-prs-20260915
fix/backup-safety-preconditions-20260915
fix/key-expiry-enforcement-20260915
fix/monitoring-contract-fixes-20260809
fix/pm2-zulip-contract-fixes-20260809
fix/agent-health-gateway-leg-deterministic-20260914
fix/probe-precision-20260914
fix/disk-gc-probe-deterministic-20260914
fix/hermes-violation-classification-20260914
fix/hermes-reachability-20260914
fix/litellm-health-timeout-and-debug-20260914
fix/litellm-health-executor-script-20260913
fix-litellm-health-keylist-20260913
fix-litellm-health-registry-20260912
fix/disk-gc-report-only-129
fix/retired-alias-sweep-20260912
fix/litellm-health-drift-20260912
fix/zulip-kagentz-adapter-20260912
fix/a2a-port-20260911
fix/decommission-router-20260911
fm/dsh-web-auth-restart-20260911
feat/memory-fixer-auto-archive-20260911
update/docker-ecosystems-20260908
fm/denya-mumuni-monitor-removal-20260910
fm/probe-drift-round2-20260909
fm/zulip-monitor-false-selfheal-20260909
fm/zulip-monitor-stream-body-20260909
provision/okyeame-cron-jobs
fm/zulip-health-contract-tanko-probe-via-am-65
fm/agent-health-probe-repoint-20260907
fix/probe-alignment-20260908
fix/zulip-creds-to-env
fix/litellm-client-timeouts
purge-gemma-fleet-wide
fix/tanko-dsh-reland
fix/infra-monitoring-dedup
fix/zulip-monitor-email-fix
fix/mumuni-normal-contracts
fix/restart-cmd-and-leftovers
fix/contracts-20260815
fix/mumuni-kagentz-repoint
fix/hermes-key-enforcement-update
hermes-key-enforcement-v1
fix/tanko-runtime
fix/infra-check-health
fix/gpu-dense-docs
fix/pm2-guard-gpu-doc
fix/hwepve-london-migration
fix/health-logs-not-graph
ship/koby-external-agent-fix
ship/enforcement-rules-reality-fix
ship/pm2-zulip-contract-fixes
ship/monitoring-contract-fixes
fix/memory-fixer-execution-v3
fix/agent-health-check
fix/gitea-logger-docs
fix/health-logs-to-gitea
fix/mumuni-hermes-gateway
fix/mumuni-ip-abiba
fix/gpu-dense-q3-correction
fix/gpu-dense-smartcode-fable5
fix/update-health-check-remove-mumuni
fix/remove-mumuni-ct114
fix/agent-health-check-v2
v16-contract-rules
fm/mumuni-recovery-hwepve
fix/pr-26-conflict
fm/captain-decision-batch-2026-07-21
feat/zulip-health-v3.1.0-koonimo
fm/prose-contracts
tune/compression-syslog-auto-v2
tune/compression-syslog-auto
fm/infra-maint-contract
feat/zulip-resilience-audit-20260718
feat/gpu-self-heal-refresh-20260718
feat/hauhaucs-gemma4-qat-20260717
feat/gpu-128k-genesis-hermes-v3-20260717
fix/vault-cleanup-contract-sync
feat/zulip-v3-resilience
feat/gpu-fleet-rebuild-20260715
feat/contract-registry
feat/gpu-workload-compression-jul2026
feat/data-source-integrity-rule
feat/ra-h-os-custodianship-contract
feat/delegation-prose-contract
fix/cron-alignment-jul2026
fix/testing-drift-jul2026
feat/consolidate-litellm-contracts
fix/litellm-contracts-jul2026
fix/contract-improvements-jul2026
feat/disk-gc-amdpve-2026-07-09
fix/infra-update-v1.1.0-regressions
feat/hermes-zulip-restore
fix/ci-checkout-ip
fix/mumuni-review-suggestions
update-key-verification-jul2026
No results found.
Labels
No items
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: SyslogSolution/prose-contracts#113
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
PR #112 merged (the six committed credentials are out of the working tree). Three follow-ups the review found, plus one thing it flagged that I verified separately.
(1)
scripts/agent-health-check.pymisattributes a missing credential as a missing secret. With neitherINFISICAL_TOKENnor~/.infisical-tokenavailable, the script now runs to completion and reports the SYMPTOM asvault secret TANKO_LITELLM_API_KEY MISSING or EMPTY/vault-empty:tanko:..., exit 1. It fails closed, so nothing is unsafe - but a reader can interpret "the secret is missing from the vault" as a deleted credential when the real condition is "this host has no vault token". The round-1 linesys.exit(1)with "INFISICAL_TOKEN not set - refusing to run with no credential" was lost in the rewrite; a one-line addition after the file-fallback distinguishes the two cases. The same authoring pattern applies to the other two scripts, which do refuse loudly - check them for consistency.(2) The same "Key Prefix" label renders a vault path in one place and a synthetic prefix in another.
agent-zero-openrouter-key.prose.md:92still has a table row| **Key Prefix** | «vault: agents/production OPENROUTER_API_KEY» |while line 57 in the same file now shows"sk-or-v1-synthetic...";litellm-api-keys.prose.md:280has the same shape under- **Prefix**:. A field that says "prefix" should hold a prefix, with the vault reference in the adjacent field.(3) Truncated key prefixes remain in the rotation history (pre-existing, not introduced by #112):
litellm-api-keys.prose.md:317-319(sk-_SWAl_Vu_,sk-OzuWsoX2…,sk-6sbCNjz,sk-BqRRMboTI…,sk-krnw_zGB,sk-OEK7z26n6E…),:334(sk-sxbphLvk1OU…) andhermes-config-template.prose.md:374. Each is a partial value rather than a credential, but they are the same class of leak in miniature and they sit in the document that teaches key hygiene. Replace with synthetic forms and say so.(4) Verified separately, no action needed:
sk-syslog-local-master-keyis documented as deprecated and it IS dead - I tested it against the gateway: 401 on both/key/listand/v1/models. So that reference is accurate documentation rather than a live credential.(5) Still with the captain, not this repo: rotation of the six exposed credentials, and the guard that fails when a credential is committed. Until the guard exists, this class will recur - this PR fixes six instances, not the cause.