docs: update key enforcement — all agents named keys, systemd fix, CI pipeline
- All 4 Hermes agents now have dedicated named LiteLLM keys (tanko, mumuni, koby, koonimo) - Documented systemd drop-in pattern fix (litellm-key.conf) - Added one-step rotation procedure - Added CI pipeline and branch protection documentation - Removed old mumuni keys, generated fresh keys for koby/koonimo
This commit is contained in:
@@ -118,14 +118,36 @@ litellm_settings:
|
|||||||
|
|
||||||
## Verified Agents (2026-07-04 final)
|
## Verified Agents (2026-07-04 final)
|
||||||
|
|
||||||
| Agent | CT | Status | api_key_env entries | Hardcoded harness | Last Verified |
|
| Agent | CT | Status | LiteLLM Alias | Key Type | Systemd Source | Last Verified |
|
||||||
|-------|-----|--------|---------------------|-------------------|---------------|
|
|-------|-----|--------|---------------|----------|----------------|---------------|
|
||||||
| Tanko | 112 | ✅ Compliant (key: tanko) | 4 | 0 | 22:45 EDT |
|
| Tanko | 112 | ✅ Compliant | `tanko` | Dedicated | `/etc/environment` only | 23:00 EDT |
|
||||||
| Mumuni | 114 | ✅ Compliant | 8 | 0 | 19:14 EDT |
|
| Mumuni | 114 | ✅ Compliant | `mumuni` | Dedicated | `/etc/environment` only | 23:00 EDT |
|
||||||
| Koby | 111 | ✅ Compliant | 14 | 0 | 19:14 EDT |
|
| Koby | 111 | ✅ Compliant | `koby` | Dedicated | User service + drop-in | 23:00 EDT |
|
||||||
| Koonimo | 113 | ✅ Compliant | 7 | 0 | 19:14 EDT |
|
| Koonimo | 113 | ✅ Compliant | `koonimo` | Dedicated | System service + drop-in | 23:00 EDT |
|
||||||
| Abiba | 100 | ✅ N/A (pi native) | — | — | 19:14 EDT |
|
| Abiba | 100 | ✅ N/A (pi native) | — | — | — | 23:00 EDT |
|
||||||
| Kagenz0 | 105 | ❌ DOWN | — | — | 19:14 EDT |
|
| Kagenz0 | 105 | ❌ DOWN | — | — | — | 19:14 EDT |
|
||||||
|
|
||||||
|
### Systemd Service Pattern (2026-07-04 fix)
|
||||||
|
|
||||||
|
All Hermes agents use systemd to manage their gateway. Two issues were fixed:
|
||||||
|
|
||||||
|
1. **Drop-in override** — `/etc/systemd/system/hermes-gateway.service.d/litellm-key.conf` (or user equivalent) had hardcoded `LITELLM_API_KEY` that bypassed `/etc/environment`.
|
||||||
|
2. **Missing EnvironmentFile** — Services did not source `/etc/environment`.
|
||||||
|
|
||||||
|
**Correct pattern:**
|
||||||
|
```ini
|
||||||
|
# In service file:
|
||||||
|
EnvironmentFile=/etc/environment
|
||||||
|
|
||||||
|
# Drop-in only for overrides, NOT primary key storage.
|
||||||
|
# If a drop-in exists, it must match /etc/environment.
|
||||||
|
```
|
||||||
|
|
||||||
|
**Rotation procedure** (one step with this standard):
|
||||||
|
1. Generate new key in LiteLLM: `curl /key/generate` with agent alias
|
||||||
|
2. Update `/etc/environment`: `sed -i 's/LITELLM_API_KEY=.*/LITELLM_API_KEY=sk-NEW/' /etc/environment`
|
||||||
|
3. Update drop-in (if exists): same sed on `litellm-key.conf`
|
||||||
|
4. Restart: `systemctl [--user] restart hermes-gateway`
|
||||||
|
|
||||||
## Violation Response
|
## Violation Response
|
||||||
|
|
||||||
@@ -141,3 +163,18 @@ litellm_settings:
|
|||||||
- `hermes-config-template.prose.md` — full configuration template
|
- `hermes-config-template.prose.md` — full configuration template
|
||||||
- `litellm-health.prose.md` — LiteLLM stack health verification
|
- `litellm-health.prose.md` — LiteLLM stack health verification
|
||||||
- `zulip-platform-verification.prose.md` — cross-platform agent verification
|
- `zulip-platform-verification.prose.md` — cross-platform agent verification
|
||||||
|
- `litellm-api-keys.prose.md` — API key creation, rotation, and verification
|
||||||
|
|
||||||
|
## CI Pipeline (2026-07-04)
|
||||||
|
|
||||||
|
All contract changes must pass the PR Pipeline before merge:
|
||||||
|
|
||||||
|
```
|
||||||
|
auth → validate → lint → ai-review → gate
|
||||||
|
```
|
||||||
|
|
||||||
|
- **Trigger**: push to master (abiba-bot only) or pull request
|
||||||
|
- **Branch protection**: Only `abiba-bot` can push directly to master. All other users must use PRs.
|
||||||
|
- **Status check**: `PR Pipeline — Authorize → Validate → Review → Merge` required before merge
|
||||||
|
- **Runner**: `runner-ct110` (Gitea Actions v0.6.1) on CT 110
|
||||||
|
- **Config**: `.gitea/workflows/pr-pipeline.yaml`
|
||||||
|
|||||||
Reference in New Issue
Block a user