hive-runtime: read the ACP provider key from bao
An opencode ACP agent got its provider API key only from the hand-placed backendEnvironmentFile. It now also reads it from the swarm secret store at swarm/agents/<agent>/acp-provider, field api_key, under its own certificate, and sets it in the spawned ACP agent's environment only. Nothing is written to disk. Precedence: a value already in the process environment (the env file) wins and the store is not asked. Otherwise the stored key is used when present. With no store, nothing stored, or a failed read, the agent is spawned without the key as before, and one line is logged without the value. The variable name comes from the existing per-agent option acp.opencode.provider.apiKeyEnv, exported as HIVE_ACP_API_KEY_ENV on the harness only for the opencode preset. Other ACP commands are unchanged. The read lives in hive-runtime, where the ACP child is spawned, so both hive-agent and hive-subagent-daemon use it. The subagent daemon unit gets the key name and, when the agent has a store, the agent's store identity (the same credentials queue-identity.nix gives the harness). No new option or setting. Closes #4841.
This commit is contained in:
parent
c2bdf30e05
commit
c5b21403a6
13 changed files with 486 additions and 9 deletions
|
|
@ -39,6 +39,29 @@ let
|
|||
claude = agentOn "claude";
|
||||
acp = agentOn "acp";
|
||||
|
||||
# The opencode preset, with and without a secret store.
|
||||
opencodeWith =
|
||||
extra:
|
||||
agentWith {
|
||||
services.hyperhive.agent = {
|
||||
runtime = "acp";
|
||||
acp.preset = "opencode";
|
||||
acp.opencode.provider.baseUrl = "https://inference.t.local/v1";
|
||||
acp.opencode.provider.apiKeyEnv = "T_PROVIDER_KEY";
|
||||
acp.opencode.model = "m";
|
||||
}
|
||||
// extra;
|
||||
};
|
||||
opencode = opencodeWith { };
|
||||
opencodeBao = opencodeWith { bao.addr = "https://bao.t.local:8200"; };
|
||||
acpBao = agentWith {
|
||||
services.hyperhive.agent = {
|
||||
runtime = "acp";
|
||||
acp.command = "/bin/agent";
|
||||
bao.addr = "https://bao.t.local:8200";
|
||||
};
|
||||
};
|
||||
|
||||
subagent = machine: machine.systemd.services.hive-subagent-daemon;
|
||||
harness = machine: machine.systemd.services.hive-agent;
|
||||
runtimeVars = [
|
||||
|
|
@ -56,6 +79,43 @@ let
|
|||
var: (subagent acp).environment.${var} or null == (harness acp).environment.${var}
|
||||
) runtimeVars;
|
||||
}
|
||||
{
|
||||
name = "an opencode agent's harness and subagent daemon are told its provider key variable";
|
||||
ok =
|
||||
(harness opencode).environment.HIVE_ACP_API_KEY_ENV == "T_PROVIDER_KEY"
|
||||
&& (subagent opencode).environment.HIVE_ACP_API_KEY_ENV == "T_PROVIDER_KEY";
|
||||
}
|
||||
{
|
||||
# Only the opencode preset has a provider key variable; any other ACP
|
||||
# command reads nothing from the store.
|
||||
name = "an ACP agent off the opencode preset is told no provider key variable";
|
||||
ok =
|
||||
!((harness acpBao).environment ? HIVE_ACP_API_KEY_ENV)
|
||||
&& (subagent acpBao).environment.HIVE_ACP_API_KEY_ENV or null == null
|
||||
&& !((subagent acpBao).serviceConfig ? LoadCredential);
|
||||
}
|
||||
{
|
||||
name = "an opencode agent's subagent daemon gets the agent's store identity";
|
||||
ok =
|
||||
let
|
||||
u = subagent opencodeBao;
|
||||
in
|
||||
u.serviceConfig.LoadCredential == [
|
||||
"hive-agent-bao-cert"
|
||||
"hive-agent-bao-key"
|
||||
"hive-agent-bao-server-ca"
|
||||
]
|
||||
&& u.environment.HIVE_AGENT_NAME == "a1"
|
||||
&& u.environment.BAO_ADDR == "https://bao.t.local:8200"
|
||||
&& u.environment.BAO_CLIENT_CERT == "%d/hive-agent-bao-cert"
|
||||
&& u.environment.BAO_CLIENT_KEY == "%d/hive-agent-bao-key";
|
||||
}
|
||||
{
|
||||
name = "an opencode agent with no store hands its subagent daemon no store identity";
|
||||
ok =
|
||||
!((subagent opencode).serviceConfig ? LoadCredential)
|
||||
&& !((subagent opencode).environment ? BAO_ADDR);
|
||||
}
|
||||
{
|
||||
name = "an ACP agent's subagent daemon loads the backend credentials";
|
||||
ok = (subagent acp).serviceConfig.EnvironmentFile or null == "-${backendEnv}";
|
||||
|
|
|
|||
Loading…
Reference in a new issue