fix(harnesses): migrate to ESO secrets_required form, mirror agent-runtimes
The CRS-served harnesses still carried `secrets_files: [{encrypted: true}]`
which now hard-fails on H-SECRET-1 ("SOPS-encrypted secrets_files entries
are no longer permitted") in the dispatcher's harness validator. Sync the
8 provider harnesses with the agent-runtimes copies: same `secrets_required`
shape, same `init.sh` (ESO-mounted file paths), same `bin/` wrappers.
Use bare `account_ref: "<provider>"` (not `<provider>.cp:cp` — that
scope-kind isn't valid per SR-DISP-1-FIELD).
Provider key names follow the per-provider schema as emitted by the CP
provisioner: minimax/airouter/z-ai → api_key; gitea-https/gitea-admin →
{token,base_url,username}; gitea-ssh* → {host,private_key}.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -18,7 +18,8 @@ ssh_hosts:
|
||||
scripts:
|
||||
init: "./init.sh"
|
||||
|
||||
secrets_files:
|
||||
- source: ./ssh-key.sops.env
|
||||
target: /opt/harness/secrets/gitea-ssh/ssh-key.sops.env
|
||||
encrypted: true
|
||||
secrets_required:
|
||||
- name: gitea-ssh
|
||||
account_ref: "gitea-ssh"
|
||||
mount_path: /run/agent/secrets/gitea-ssh
|
||||
mode: "0400"
|
||||
|
||||
Reference in New Issue
Block a user