hive-runtime: read the ACP provider key from bao
An opencode ACP agent got its provider API key only from the hand-placed backendEnvironmentFile. It now also reads it from the swarm secret store at swarm/agents/<agent>/acp-provider, field api_key, under its own certificate, and sets it in the spawned ACP agent's environment only. Nothing is written to disk. Precedence: a value already in the process environment (the env file) wins and the store is not asked. Otherwise the stored key is used when present. With no store, nothing stored, or a failed read, the agent is spawned without the key as before, and one line is logged without the value. The variable name comes from the existing per-agent option acp.opencode.provider.apiKeyEnv, exported as HIVE_ACP_API_KEY_ENV on the harness only for the opencode preset. Other ACP commands are unchanged. The read lives in hive-runtime, where the ACP child is spawned, so both hive-agent and hive-subagent-daemon use it. The subagent daemon unit gets the key name and, when the agent has a store, the agent's store identity (the same credentials queue-identity.nix gives the harness). No new option or setting. Closes #4841.
This commit is contained in:
parent
c2bdf30e05
commit
c5b21403a6
13 changed files with 486 additions and 9 deletions
|
|
@ -12,6 +12,7 @@ use tokio::io::{AsyncBufReadExt, AsyncWriteExt, BufReader};
|
|||
use tokio::process::{Child, ChildStdin, Command};
|
||||
use tokio::sync::{mpsc, oneshot};
|
||||
|
||||
use super::provider_key::KeyVar;
|
||||
use super::stream::mcp_server_of;
|
||||
use super::{AcpError, PermissionAsk, PermissionPolicy};
|
||||
use crate::spec::AcpCommand;
|
||||
|
|
@ -38,16 +39,21 @@ pub(super) struct Connection {
|
|||
}
|
||||
|
||||
impl Connection {
|
||||
/// Spawn the agent in `cwd` and start reading its output.
|
||||
/// Spawn the agent in `cwd`, with `key` added to its environment, and
|
||||
/// start reading its output.
|
||||
pub(super) fn spawn(
|
||||
command: &AcpCommand,
|
||||
key: Option<&KeyVar>,
|
||||
cwd: &Path,
|
||||
permit: PermissionPolicy,
|
||||
servers: Vec<String>,
|
||||
) -> Result<Self, AcpError> {
|
||||
let mut child = Command::new(&command.command)
|
||||
.args(&command.args)
|
||||
.envs(&command.env)
|
||||
let mut cmd = Command::new(&command.command);
|
||||
cmd.args(&command.args).envs(&command.env);
|
||||
if let Some(key) = key {
|
||||
cmd.env(&key.name, &key.value);
|
||||
}
|
||||
let mut child = cmd
|
||||
.current_dir(cwd)
|
||||
.stdin(Stdio::piped())
|
||||
.stdout(Stdio::piped())
|
||||
|
|
|
|||
Loading…
Reference in a new issue