The consumer half of the OTHER model-access shape. Where anthropic-consumer receives a refreshed access token, this receives one operator-supplied API key the mesh sealed to it and the host unsealed at its secret path — no manager, no refresh, no usage. It writes the key where an OpenAI/Codex client reads it: an OPENAI_API_KEY env file and the publicly-known Codex auth.json. Pure node, no SDK import — the simplest a model-access consumer gets. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
52 lines
1.3 KiB
JSON
52 lines
1.3 KiB
JSON
{
|
|
"module": "openai-consumer",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"model-access"
|
|
],
|
|
"binds": {
|
|
"model-access": "/var/lib/openai-consumer/model.json"
|
|
},
|
|
"secrets": {
|
|
"model-access": "/var/lib/openai-consumer/api-key"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/openai-consumer",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "directory",
|
|
"path": "/var/lib/openai-consumer/config",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "apply",
|
|
"type": "container",
|
|
"name": "mesh-openai-consumer-apply",
|
|
"image": "mesh-runtime-openai-consumer@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
|
"network": "host",
|
|
"schedule": "*/5 * * * *",
|
|
"args": [
|
|
"run",
|
|
"/app/modules/openai-consumer/dist/apply/index.js"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/openai-consumer:/run/state"
|
|
],
|
|
"env": {
|
|
"MESH_MODEL_ACCESS_SECRET_FILE": "/run/state/api-key",
|
|
"MESH_MODEL_ACCESS_BIND_FILE": "/run/state/model.json",
|
|
"MESH_OPENAI_ENV_FILE": "/run/state/config/openai.env",
|
|
"MESH_OPENAI_CREDENTIALS_FILE": "/run/state/config/auth.json"
|
|
}
|
|
}
|
|
]
|
|
}
|