Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/hive-runtime/src/acp
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas c5b21403a6 hive-runtime: read the ACP provider key from bao
An opencode ACP agent got its provider API key only from the hand-placed
backendEnvironmentFile. It now also reads it from the swarm secret store
at swarm/agents/<agent>/acp-provider, field api_key, under its own
certificate, and sets it in the spawned ACP agent's environment only.
Nothing is written to disk.

Precedence: a value already in the process environment (the env file)
wins and the store is not asked. Otherwise the stored key is used when
present. With no store, nothing stored, or a failed read, the agent is
spawned without the key as before, and one line is logged without the
value.

The variable name comes from the existing per-agent option
acp.opencode.provider.apiKeyEnv, exported as HIVE_ACP_API_KEY_ENV on the
harness only for the opencode preset. Other ACP commands are unchanged.

The read lives in hive-runtime, where the ACP child is spawned, so both
hive-agent and hive-subagent-daemon use it. The subagent daemon unit
gets the key name and, when the agent has a store, the agent's store
identity (the same credentials queue-identity.nix gives the harness).

No new option or setting. Closes #4841.
2026-09-30 22:55:03 +02:00
..
mod.rs hive-runtime: read the ACP provider key from bao 2026-09-30 22:55:03 +02:00
provider_key.rs hive-runtime: read the ACP provider key from bao 2026-09-30 22:55:03 +02:00
rpc.rs hive-runtime: read the ACP provider key from bao 2026-09-30 22:55:03 +02:00
stream.rs hive-agent: export ACP-reported cost and context fill over OTLP 2026-09-30 22:24:06 +02:00