hive-runtime: read the ACP provider key from bao
An opencode ACP agent got its provider API key only from the hand-placed backendEnvironmentFile. It now also reads it from the swarm secret store at swarm/agents/<agent>/acp-provider, field api_key, under its own certificate, and sets it in the spawned ACP agent's environment only. Nothing is written to disk. Precedence: a value already in the process environment (the env file) wins and the store is not asked. Otherwise the stored key is used when present. With no store, nothing stored, or a failed read, the agent is spawned without the key as before, and one line is logged without the value. The variable name comes from the existing per-agent option acp.opencode.provider.apiKeyEnv, exported as HIVE_ACP_API_KEY_ENV on the harness only for the opencode preset. Other ACP commands are unchanged. The read lives in hive-runtime, where the ACP child is spawned, so both hive-agent and hive-subagent-daemon use it. The subagent daemon unit gets the key name and, when the agent has a store, the agent's store identity (the same credentials queue-identity.nix gives the harness). No new option or setting. Closes #4841.
This commit is contained in:
parent
c2bdf30e05
commit
c5b21403a6
13 changed files with 486 additions and 9 deletions
|
|
@ -210,6 +210,10 @@ in
|
|||
restored — makes systemd skip it rather than refuse to start the
|
||||
harness. See `services.hyperhive.agent.useApiKey`'s doc for the option this one is
|
||||
paired with.
|
||||
|
||||
On an ACP agent using the `opencode` preset, a provider key this file
|
||||
leaves unset is read from the swarm secret store at
|
||||
`swarm/agents/<agent>/acp-provider`, field `api_key`, if one is stored.
|
||||
'';
|
||||
};
|
||||
|
||||
|
|
@ -325,7 +329,9 @@ in
|
|||
default = "ACP_PROVIDER_API_KEY";
|
||||
description = ''
|
||||
Environment variable opencode reads the provider's API key from.
|
||||
Set it in `services.hyperhive.agent.backendEnvironmentFile`.
|
||||
Set it in `services.hyperhive.agent.backendEnvironmentFile`, or store
|
||||
the key in the swarm secret store at
|
||||
`swarm/agents/<agent>/acp-provider`, field `api_key`.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
|
@ -519,6 +525,11 @@ in
|
|||
HIVE_ACP_COMMAND = acp.command;
|
||||
HIVE_ACP_ARGS = builtins.toJSON acp.args;
|
||||
HIVE_ACP_ENV = builtins.toJSON acp.env;
|
||||
}
|
||||
// lib.optionalAttrs (isAcp && acp.preset == "opencode") {
|
||||
# Read by `hive_runtime`, which fills it from the store when the
|
||||
# environment leaves it unset.
|
||||
HIVE_ACP_API_KEY_ENV = oc.provider.apiKeyEnv;
|
||||
};
|
||||
serviceConfig = {
|
||||
ExecStart = "${config.services.hyperhive.agent.packages.hive-agent}/bin/${binary}";
|
||||
|
|
|
|||
Loading…
Reference in a new issue