Render Hermes router API key safely

This commit is contained in:
Mikei386
2026-08-24 22:40:02 +02:00
parent 53f10d1d3f
commit a8ae77dbc3
2 changed files with 34 additions and 0 deletions
+19
View File
@@ -2,6 +2,8 @@
set -Eeuo pipefail
HERMES_CONTAINER=${HERMES_CONTAINER:-mike-ai-hermes}
SECRETS_DIR=${SECRETS_DIR:-/etc/mike-ai}
HERMES_DATA_DIR=${HERMES_DATA_DIR:-/data/hermes}
die() { printf 'FEHLER: %s\n' "$*" >&2; exit 1; }
docker inspect "$HERMES_CONTAINER" >/dev/null 2>&1 || \
@@ -39,6 +41,23 @@ create_profile ultra qwen-ultra 262144 \
create_profile uncensored qwen-uncensored 80000 \
"Unzensiertes Qwen3.8-27B-Profil mit 80K Kontext fuer spezielle Anfragen."
# Existing profiles may predate managed secret rendering and therefore contain
# the literal ${ROUTER_API_KEY}. Repair only that exact placeholder; never log
# or commit the secret itself.
[[ -s $SECRETS_DIR/router-api-key ]] || die "Router-API-Key fehlt."
router_key=$(<"$SECRETS_DIR/router-api-key")
ROUTER_API_KEY="$router_key" HERMES_DATA_DIR="$HERMES_DATA_DIR" python3 <<'PY'
import os
import pathlib
root = pathlib.Path(os.environ["HERMES_DATA_DIR"]) / "profiles"
placeholder = "${ROUTER_API_KEY}"
for path in sorted(root.glob("*/config.yaml")):
text = path.read_text()
if placeholder in text:
path.write_text(text.replace(placeholder, os.environ["ROUTER_API_KEY"], 1))
PY
"${STACK_DIR:-/opt/mike-ai/stack}/platform/hermes/install-skills.sh"
docker exec "$HERMES_CONTAINER" hermes profile list
printf 'HERMES_PROFILES_OK\n'