Mirrors agent-runtimes commit 6f20b51. CRS serves these harness files to dispatchers, so this repo must match. Switches from "mount mode 0444 so the agent user can `cat` the ESO file" to the gitea-ssh staging pattern: keep the ESO mount root-only (0400), init.sh as root `install`s a per-secret 0600 agent-owned copy, and apiKeyHelper points at the staged copy. Stronger blast-radius guarantee — if the ESO Secret later grows additional keys, they remain root-only unless the harness explicitly stages them. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2.5 KiB
Executable File
2.5 KiB
Executable File