#!/bin/bash # z-ai init — write ~/.claude/settings.json with apiKeyHelper. # # The Z.ai auth_token is mounted by ESO at # /run/agent/secrets/z-ai/auth_token (mode 0400, secrets_required entry in # harness.yaml). Claude Code's `apiKeyHelper` setting names a command that # prints the key on stdout when the CLI needs it for an API request — the # value never enters this process' environment, never appears in the claude # subprocess' /proc//environ, and is read fresh on each invocation so # ESO secret rotations are picked up without a process restart. # # When ANTHROPIC_BASE_URL points at a non-anthropic.com host (set in # harness.yaml to https://api.z.ai/api/anthropic), Claude Code routes # apiKeyHelper output to `Authorization: Bearer `, which is the # header shape the Z.ai proxy requires. # # The K8s Secret may also contain a `base_url` file (legacy from the # wrapper-script era) — it is intentionally ignored. The base URL is not a # credential; it lives in harness.yaml. set -euo pipefail API_KEY_FILE="/run/agent/secrets/z-ai/auth_token" if [ ! -r "$API_KEY_FILE" ]; then echo "ERROR: $API_KEY_FILE not readable. Check ESO ExternalSecret acct-." >&2 exit 1 fi CONFIG_DIR="${CLAUDE_CONFIG_DIR:-$HOME/.claude}" mkdir -p "$CONFIG_DIR" chmod 0700 "$CONFIG_DIR" SETTINGS_FILE="$CONFIG_DIR/settings.json" # Merge into an existing settings.json (from another harness layer) when # possible; otherwise create a fresh one. if [ -f "$SETTINGS_FILE" ] && command -v jq >/dev/null 2>&1; then TMP=$(mktemp) jq --arg helper "cat $API_KEY_FILE" \ '. + {apiKeyHelper: $helper}' \ "$SETTINGS_FILE" > "$TMP" mv "$TMP" "$SETTINGS_FILE" else cat > "$SETTINGS_FILE" <