Files
agent-runtime-framework/harnesses/contexts/gitea-ssh-homelab/v1/init.sh
Paul O'Reilly 5f85d895c1 fix(harnesses): migrate to ESO secrets_required form, mirror agent-runtimes
The CRS-served harnesses still carried `secrets_files: [{encrypted: true}]`
which now hard-fails on H-SECRET-1 ("SOPS-encrypted secrets_files entries
are no longer permitted") in the dispatcher's harness validator. Sync the
8 provider harnesses with the agent-runtimes copies: same `secrets_required`
shape, same `init.sh` (ESO-mounted file paths), same `bin/` wrappers.

Use bare `account_ref: "<provider>"` (not `<provider>.cp:cp` — that
scope-kind isn't valid per SR-DISP-1-FIELD).

Provider key names follow the per-provider schema as emitted by the CP
provisioner: minimax/airouter/z-ai → api_key; gitea-https/gitea-admin →
{token,base_url,username}; gitea-ssh* → {host,private_key}.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-07 07:26:19 +12:00

31 lines
1.3 KiB
Bash
Executable File

#!/bin/bash
# gitea-ssh-homelab init: copy the ESO-mounted SSH key to the path the
# harness-init `~/.ssh/config` expects.
#
# The harness-init dispatcher (`entrypoint/harness_init.py`) writes
# `~/.ssh/config` from the harness's `ssh_hosts:` block; for this provider
# the entry is `Host gitea.oreillyit.nz-homelab` with
# `IdentityFile /home/agent/.ssh/gitea-oreillyit-nz-homelab`.
#
# We only need to materialise the key file at that path. We MUST NOT append
# our own SSH config block — doing so would (a) duplicate harness-init's
# config (SSH first-match-wins, so the appended block becomes dead) and
# (b) any unaliased `Host gitea.oreillyit.nz` block would collide with
# other gitea harnesses (gitea-https, gitea-admin) when composed.
#
# Per H-SECRET-4: NO `export` of credentials here. The path to the key is
# not a secret; the key content is, and it stays in the file.
set -euo pipefail
SSH_KEY_SRC="/run/agent/secrets/gitea-ssh-homelab/id_ed25519"
SSH_KEY_DST="/home/agent/.ssh/gitea-oreillyit-nz-homelab"
if [ ! -r "$SSH_KEY_SRC" ]; then
echo "ERROR: SSH key not found at $SSH_KEY_SRC — ESO ExternalSecret not Ready?" >&2
exit 1
fi
mkdir -p /home/agent/.ssh
install -m 0600 -o agent -g agent "$SSH_KEY_SRC" "$SSH_KEY_DST"
echo "gitea-ssh-homelab: SSH key staged at $SSH_KEY_DST (0600 agent:agent)"