Mark the OpenAI keys letta and supabase hold as issued outside the mesh

The controller now replaces a given at-start secret after the module's
first good start and on rotate (hq ADR 0228); a key only OpenAI can
issue must say so, or a fresh random value would take its place.
This commit is contained in:
jochen
2026-10-06 12:13:57 +02:00
parent aabc8aa039
commit b1bd5c861e
2 changed files with 6 additions and 2 deletions
+2 -1
View File
@@ -34,7 +34,8 @@
},
"openai-api-key": {
"path": "${dir:state}/openai-api-key.secret",
"taken": "at-start"
"taken": "at-start",
"issued-by": "outside"
}
},
"listens": [
+4 -1
View File
@@ -44,7 +44,10 @@
"pooler-vault": "${dir:state}/pooler-vault.secret",
"key-base-a": "${dir:state}/key-base-a.secret",
"key-base-b": "${dir:state}/key-base-b.secret",
"openai": "${dir:state}/openai.secret"
"openai": {
"path": "${dir:state}/openai.secret",
"issued-by": "outside"
}
},
"contributes": {
"route": {