fix(harnesses): migrate to ESO secrets_required form, mirror agent-runtimes

The CRS-served harnesses still carried `secrets_files: [{encrypted: true}]`
which now hard-fails on H-SECRET-1 ("SOPS-encrypted secrets_files entries
are no longer permitted") in the dispatcher's harness validator. Sync the
8 provider harnesses with the agent-runtimes copies: same `secrets_required`
shape, same `init.sh` (ESO-mounted file paths), same `bin/` wrappers.

Use bare `account_ref: "<provider>"` (not `<provider>.cp:cp` — that
scope-kind isn't valid per SR-DISP-1-FIELD).

Provider key names follow the per-provider schema as emitted by the CP
provisioner: minimax/airouter/z-ai → api_key; gitea-https/gitea-admin →
{token,base_url,username}; gitea-ssh* → {host,private_key}.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Paul O'Reilly
2026-05-07 07:26:19 +12:00
parent 8bbf6cbb2f
commit 5f85d895c1
20 changed files with 288 additions and 117 deletions

View File

@@ -0,0 +1,12 @@
#!/bin/bash
# z-ai Anthropic-compatible wrapper — injects ESO-mounted credentials
# M22 Phase 9 Wave 4
# Files at /run/agent/secrets/z-ai/ are mounted by the dispatcher via ESO K8s Secret
set -euo pipefail
SECRETS_DIR="/run/agent/secrets/z-ai"
exec env \
ANTHROPIC_AUTH_TOKEN="$(cat "$SECRETS_DIR/auth_token")" \
ANTHROPIC_BASE_URL="$(cat "$SECRETS_DIR/base_url")" \
claude "$@"

View File

@@ -11,9 +11,13 @@ env:
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC: "1"
DISABLE_PROMPT_CACHING: "1"
secrets_files:
- source: ./provider.sops.env
target: /opt/harness/secrets/z-ai/provider.sops.env
encrypted: true
secrets_required:
- name: z-ai
account_ref: "z-ai"
mount_path: /run/agent/secrets/z-ai
mode: "0400"
scripts:
init: "./init.sh"
# TODO: Add network_hosts for api.z.ai when context harnesses support it

View File

@@ -0,0 +1,16 @@
#!/bin/bash
# z-ai harness init — verifies ESO secret mount exists
# M22 Phase 9 Wave 4
set -euo pipefail
echo "=== z-ai/v1 init ==="
SECRETS_DIR="/run/agent/secrets/z-ai"
if [ ! -d "$SECRETS_DIR" ]; then
echo "ERROR: ESO secret mount not found at $SECRETS_DIR" >&2
echo "Has the dispatcher been configured with ESO-managed secrets?" >&2
exit 1
fi
echo "z-ai ESO secret mount verified at $SECRETS_DIR"
echo "=== z-ai/v1 init complete ==="