Render Hermes router API key safely
This commit is contained in:
@@ -57,6 +57,21 @@ if [[ -s $HERMES_DATA_DIR/config.yaml ]] && \
|
|||||||
"$HERMES_DATA_DIR/config.yaml.before-managed-update-$(date +%Y%m%d-%H%M%S)"
|
"$HERMES_DATA_DIR/config.yaml.before-managed-update-$(date +%Y%m%d-%H%M%S)"
|
||||||
fi
|
fi
|
||||||
install -m 0600 "$STACK_DIR/platform/hermes/config.yaml" "$HERMES_DATA_DIR/config.yaml"
|
install -m 0600 "$STACK_DIR/platform/hermes/config.yaml" "$HERMES_DATA_DIR/config.yaml"
|
||||||
|
# Hermes expands environment variables in some runtime paths, but model.api_key
|
||||||
|
# is persisted and reloaded literally when a client changes the model. Render
|
||||||
|
# this one managed placeholder before the configuration becomes live.
|
||||||
|
ROUTER_API_KEY="$router_key" python3 - "$HERMES_DATA_DIR/config.yaml" <<'PY'
|
||||||
|
import os
|
||||||
|
import pathlib
|
||||||
|
import sys
|
||||||
|
|
||||||
|
path = pathlib.Path(sys.argv[1])
|
||||||
|
text = path.read_text()
|
||||||
|
placeholder = "${ROUTER_API_KEY}"
|
||||||
|
if placeholder not in text:
|
||||||
|
raise SystemExit("ROUTER_API_KEY placeholder missing from managed Hermes config")
|
||||||
|
path.write_text(text.replace(placeholder, os.environ["ROUTER_API_KEY"], 1))
|
||||||
|
PY
|
||||||
install -m 0600 "$STACK_DIR/platform/hermes/SOUL.md" "$HERMES_DATA_DIR/SOUL.md"
|
install -m 0600 "$STACK_DIR/platform/hermes/SOUL.md" "$HERMES_DATA_DIR/SOUL.md"
|
||||||
chown -R 10000:10000 "$HERMES_DATA_DIR"
|
chown -R 10000:10000 "$HERMES_DATA_DIR"
|
||||||
"$STACK_DIR/platform/hermes/install-skills.sh"
|
"$STACK_DIR/platform/hermes/install-skills.sh"
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
set -Eeuo pipefail
|
set -Eeuo pipefail
|
||||||
|
|
||||||
HERMES_CONTAINER=${HERMES_CONTAINER:-mike-ai-hermes}
|
HERMES_CONTAINER=${HERMES_CONTAINER:-mike-ai-hermes}
|
||||||
|
SECRETS_DIR=${SECRETS_DIR:-/etc/mike-ai}
|
||||||
|
HERMES_DATA_DIR=${HERMES_DATA_DIR:-/data/hermes}
|
||||||
|
|
||||||
die() { printf 'FEHLER: %s\n' "$*" >&2; exit 1; }
|
die() { printf 'FEHLER: %s\n' "$*" >&2; exit 1; }
|
||||||
docker inspect "$HERMES_CONTAINER" >/dev/null 2>&1 || \
|
docker inspect "$HERMES_CONTAINER" >/dev/null 2>&1 || \
|
||||||
@@ -39,6 +41,23 @@ create_profile ultra qwen-ultra 262144 \
|
|||||||
create_profile uncensored qwen-uncensored 80000 \
|
create_profile uncensored qwen-uncensored 80000 \
|
||||||
"Unzensiertes Qwen3.8-27B-Profil mit 80K Kontext fuer spezielle Anfragen."
|
"Unzensiertes Qwen3.8-27B-Profil mit 80K Kontext fuer spezielle Anfragen."
|
||||||
|
|
||||||
|
# Existing profiles may predate managed secret rendering and therefore contain
|
||||||
|
# the literal ${ROUTER_API_KEY}. Repair only that exact placeholder; never log
|
||||||
|
# or commit the secret itself.
|
||||||
|
[[ -s $SECRETS_DIR/router-api-key ]] || die "Router-API-Key fehlt."
|
||||||
|
router_key=$(<"$SECRETS_DIR/router-api-key")
|
||||||
|
ROUTER_API_KEY="$router_key" HERMES_DATA_DIR="$HERMES_DATA_DIR" python3 <<'PY'
|
||||||
|
import os
|
||||||
|
import pathlib
|
||||||
|
|
||||||
|
root = pathlib.Path(os.environ["HERMES_DATA_DIR"]) / "profiles"
|
||||||
|
placeholder = "${ROUTER_API_KEY}"
|
||||||
|
for path in sorted(root.glob("*/config.yaml")):
|
||||||
|
text = path.read_text()
|
||||||
|
if placeholder in text:
|
||||||
|
path.write_text(text.replace(placeholder, os.environ["ROUTER_API_KEY"], 1))
|
||||||
|
PY
|
||||||
|
|
||||||
"${STACK_DIR:-/opt/mike-ai/stack}/platform/hermes/install-skills.sh"
|
"${STACK_DIR:-/opt/mike-ai/stack}/platform/hermes/install-skills.sh"
|
||||||
docker exec "$HERMES_CONTAINER" hermes profile list
|
docker exec "$HERMES_CONTAINER" hermes profile list
|
||||||
printf 'HERMES_PROFILES_OK\n'
|
printf 'HERMES_PROFILES_OK\n'
|
||||||
|
|||||||
Reference in New Issue
Block a user