Mirrors agent-runtimes commit 6f20b51. CRS serves these harness files to dispatchers, so this repo must match. Switches from "mount mode 0444 so the agent user can `cat` the ESO file" to the gitea-ssh staging pattern: keep the ESO mount root-only (0400), init.sh as root `install`s a per-secret 0600 agent-owned copy, and apiKeyHelper points at the staged copy. Stronger blast-radius guarantee — if the ESO Secret later grows additional keys, they remain root-only unless the harness explicitly stages them. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
32 lines
1.1 KiB
YAML
32 lines
1.1 KiB
YAML
kind: context
|
|
name: minimax
|
|
version: 1
|
|
description: "MiniMax coding plan — Anthropic-compatible proxy"
|
|
requires: []
|
|
provides: [claude-code]
|
|
|
|
# Auth is wired by init.sh via Claude Code's apiKeyHelper (settings.json).
|
|
# No credential env vars: the secret stays in the mounted file and is read
|
|
# only by the helper command at request time.
|
|
env:
|
|
ANTHROPIC_BASE_URL: "https://api.minimax.io/anthropic"
|
|
CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS: "1"
|
|
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC: "1"
|
|
DISABLE_PROMPT_CACHING: "1"
|
|
|
|
secrets_required:
|
|
- name: minimax
|
|
account_ref: "minimax"
|
|
mount_path: /run/agent/secrets/minimax
|
|
# 0400 (root-only) — defense in depth. The agent user CANNOT read this
|
|
# mount. init.sh runs as root and `install`s a per-secret copy into the
|
|
# agent's home with mode 0600 owned by agent; only that copy is exposed
|
|
# to the runtime. Matches the gitea-ssh pattern. If the ESO Secret
|
|
# later grows additional keys, they remain inaccessible by default.
|
|
mode: "0400"
|
|
|
|
scripts:
|
|
init: ./init.sh
|
|
|
|
# TODO: Add network_hosts for api.minimax.io when context harnesses support it
|