fix(keys): correct the key-lifecycle contracts to the measured truth #95

Merged
abiba-bot merged 5 commits from fix/key-expiry-enforcement-20260915 into master 2026-09-15 05:37:46 +00:00
Showing only changes of commit dd9e68329e - Show all commits
+3 -3
View File
@@ -324,10 +324,10 @@ directly call OpenRouter via Python's requests library. Converting would require
```bash
# Read at runtime from the container's environment:
docker exec harness-litellm printenv LITELLM_MASTER_KEY
# Or from Infisical vault (project=infrastructure env=prod):
infisical secrets get LITELLM_MASTER_KEY --project=infrastructure --env=production --plain
# Or from Infisical vault (project=infrastructure env=prod) - NOTE: --plain is broken on CLI 0.43.110 (prints nothing):
infisical secrets get LITELLM_MASTER_KEY --project=infrastructure --env=production | awk '$1=="LITELLM_MASTER_KEY"{print $NF}'
# Prove a key is live with a 200 from /key/list on the CT 116 host (the container has no curl):
curl -s -H "Authorization: Bearer <key>" http://192.168.68.116/litellm/key/list | jq length
curl -s -H "Authorization: Bearer <key>" http://127.0.0.1:4000/key/list | jq length
```
- Used for /key/generate, /key/delete, /key/list (GET), DB queries
- **Known violation (RESOLVED 2026-07-16):** Abiba's LITELLM_API_KEY was previously the master key.