Mirrors agent-runtimes commit 166c19b. CRS serves these harness files to dispatchers, so this repo must match. Two fixes from the failing smoke test: 1. init.sh resolves the agent user's home via getent (init.sh runs as root, but claude runs as the agent user — different $HOME). 2. secrets_required mode "0400" → "0444" so the agent user can read the ESO-mounted secret via apiKeyHelper. The file is in pod-local tmpfs. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
32 lines
1.1 KiB
YAML
32 lines
1.1 KiB
YAML
kind: context
|
|
name: minimax
|
|
version: 1
|
|
description: "MiniMax coding plan — Anthropic-compatible proxy"
|
|
requires: []
|
|
provides: [claude-code]
|
|
|
|
# Auth is wired by init.sh via Claude Code's apiKeyHelper (settings.json).
|
|
# No credential env vars: the secret stays in the mounted file and is read
|
|
# only by the helper command at request time.
|
|
env:
|
|
ANTHROPIC_BASE_URL: "https://api.minimax.io/anthropic"
|
|
CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS: "1"
|
|
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC: "1"
|
|
DISABLE_PROMPT_CACHING: "1"
|
|
|
|
secrets_required:
|
|
- name: minimax
|
|
account_ref: "minimax"
|
|
mount_path: /run/agent/secrets/minimax
|
|
# 0444 — readable by the agent user that runs `claude` (and thus
|
|
# apiKeyHelper). The pod has no fsGroup, so the kubelet mounts the
|
|
# secret as root:root; mode 0400 would block the legitimate read.
|
|
# The file lives in pod-local tmpfs — "world readable" only means
|
|
# readable by other processes in this same pod, which we control.
|
|
mode: "0444"
|
|
|
|
scripts:
|
|
init: ./init.sh
|
|
|
|
# TODO: Add network_hosts for api.minimax.io when context harnesses support it
|