The CRS-served harnesses still carried `secrets_files: [{encrypted: true}]`
which now hard-fails on H-SECRET-1 ("SOPS-encrypted secrets_files entries
are no longer permitted") in the dispatcher's harness validator. Sync the
8 provider harnesses with the agent-runtimes copies: same `secrets_required`
shape, same `init.sh` (ESO-mounted file paths), same `bin/` wrappers.
Use bare `account_ref: "<provider>"` (not `<provider>.cp:cp` — that
scope-kind isn't valid per SR-DISP-1-FIELD).
Provider key names follow the per-provider schema as emitted by the CP
provisioner: minimax/airouter/z-ai → api_key; gitea-https/gitea-admin →
{token,base_url,username}; gitea-ssh* → {host,private_key}.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
19 lines
583 B
Bash
Executable File
19 lines
583 B
Bash
Executable File
#!/bin/bash
|
|
set -euo pipefail
|
|
|
|
# Verify the ESO-managed MiniMax api_key file is mounted. The wrapper
|
|
# (`bin/anthropic-compat-wrapper.sh`) reads it at exec time and exports
|
|
# ANTHROPIC_AUTH_TOKEN to the claude subprocess.
|
|
#
|
|
# ANTHROPIC_BASE_URL is set in harness.yaml `env:` (not in the K8s Secret),
|
|
# so no file check is required for it.
|
|
|
|
API_KEY_FILE="/run/agent/secrets/minimax/api_key"
|
|
|
|
if [ ! -r "$API_KEY_FILE" ]; then
|
|
echo "ERROR: $API_KEY_FILE not readable. Check ESO ExternalSecret acct-<minimax-id>." >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "minimax api_key verified at $API_KEY_FILE"
|