hive-runtime: read the ACP provider key from bao
An opencode ACP agent got its provider API key only from the hand-placed backendEnvironmentFile. It now also reads it from the swarm secret store at swarm/agents/<agent>/acp-provider, field api_key, under its own certificate, and sets it in the spawned ACP agent's environment only. Nothing is written to disk. Precedence: a value already in the process environment (the env file) wins and the store is not asked. Otherwise the stored key is used when present. With no store, nothing stored, or a failed read, the agent is spawned without the key as before, and one line is logged without the value. The variable name comes from the existing per-agent option acp.opencode.provider.apiKeyEnv, exported as HIVE_ACP_API_KEY_ENV on the harness only for the opencode preset. Other ACP commands are unchanged. The read lives in hive-runtime, where the ACP child is spawned, so both hive-agent and hive-subagent-daemon use it. The subagent daemon unit gets the key name and, when the agent has a store, the agent's store identity (the same credentials queue-identity.nix gives the harness). No new option or setting. Closes #4841.
This commit is contained in:
parent
c2bdf30e05
commit
c5b21403a6
13 changed files with 486 additions and 9 deletions
|
|
@ -11,6 +11,10 @@ pub const ACP_ARGS_ENV: &str = "HIVE_ACP_ARGS";
|
|||
/// Extra environment for the ACP agent only, as a JSON object of strings.
|
||||
/// Optional. The agent also inherits the harness's own environment.
|
||||
pub const ACP_ENV_ENV: &str = "HIVE_ACP_ENV";
|
||||
/// The variable the ACP agent reads its provider API key from. Optional. When
|
||||
/// set and the process environment leaves that variable unset, the agent is
|
||||
/// spawned with it read from the swarm secret store.
|
||||
pub const ACP_API_KEY_ENV_ENV: &str = "HIVE_ACP_API_KEY_ENV";
|
||||
|
||||
/// The runtime an agent is configured with.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
|
|
@ -25,6 +29,8 @@ pub struct AcpCommand {
|
|||
pub command: String,
|
||||
pub args: Vec<String>,
|
||||
pub env: BTreeMap<String, String>,
|
||||
/// See [`ACP_API_KEY_ENV_ENV`].
|
||||
pub api_key_env: Option<String>,
|
||||
}
|
||||
|
||||
/// A runtime configuration that cannot be acted on.
|
||||
|
|
@ -63,6 +69,7 @@ impl RuntimeSpec {
|
|||
command,
|
||||
args: json_or_default(&lookup, ACP_ARGS_ENV)?,
|
||||
env: json_or_default(&lookup, ACP_ENV_ENV)?,
|
||||
api_key_env: lookup(ACP_API_KEY_ENV_ENV).filter(|v| !v.trim().is_empty()),
|
||||
}))
|
||||
}
|
||||
other => Err(SpecError::UnknownRuntime(other.to_owned())),
|
||||
|
|
@ -119,6 +126,7 @@ mod tests {
|
|||
"HIVE_ACP_ENV",
|
||||
r#"{"AGENT_CONFIG":"/nix/store/y/config.json"}"#,
|
||||
),
|
||||
("HIVE_ACP_API_KEY_ENV", "ACP_PROVIDER_API_KEY"),
|
||||
])
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
|
|
@ -127,6 +135,7 @@ mod tests {
|
|||
command: "/nix/store/x/bin/agent".into(),
|
||||
args: vec!["acp".into(), "--flag".into()],
|
||||
env: [("AGENT_CONFIG".into(), "/nix/store/y/config.json".into())].into(),
|
||||
api_key_env: Some("ACP_PROVIDER_API_KEY".into()),
|
||||
})
|
||||
);
|
||||
}
|
||||
|
|
@ -139,6 +148,7 @@ mod tests {
|
|||
};
|
||||
assert!(cmd.args.is_empty());
|
||||
assert!(cmd.env.is_empty());
|
||||
assert_eq!(cmd.api_key_env, None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
|
|
|||
Loading…
Reference in a new issue