meshai/.gitignore
malice 3495eb31de
feat(secrets): GUI-managed .env secrets store — keys are config, but gitignored (#47)
API keys/secrets now live in /data/secrets/.env (gitignored, never in config
YAML), while remaining fully editable from the dashboard. Config YAML holds
only ${VAR} references.

Backend:
- meshai/secrets_store.py: get_status (SET/NOT-SET, never values), set_secret,
  delete_secret over /data/secrets/.env (resolved like load_config); authoritative
  SECRET_FIELD_TO_ENV map (traffic→TOMTOM_API_KEY, firms→FIRMS_MAP_KEY,
  roads511→ROADS511_API_KEY, wzdx→WZDX_API_KEY, smtp→SMTP_PASSWORD,
  mesh_sources→MESHMONITOR_API_TOKEN) + backend-dependent llm_env_var
- dashboard/api/secrets_routes.py: GET /api/secrets (status only), PUT/DELETE
  /api/secrets/{env_var} (validated, restart_required); registered in server.py
- config_loader: save_section preserves ${VAR} secret refs on section save
  (never rejects them); EXPECTED_SECRETS += ROADS511_API_KEY, WZDX_API_KEY
- config.example.yaml + docker-entrypoint default config use ${VAR} refs;
  first-run bootstraps /data/secrets/.env; .gitignore covers it

Frontend:
- components/ManagedSecret.tsx: masked, Set/Not-set badge, reveal, Save->PUT,
  "restart required"; carries no config value so secrets never enter a section
  save payload
- wired into Environment (tomtom/roads511/wzdx/firms), Config LLM tab
  (env var by backend), Notifications (smtp)

Restart required after a secret change (env read at config-load). 11 store
tests; suite at 10-failure baseline (1714 passed).

Co-authored-by: Matt Johnson <mj@k7zvx.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-05 17:57:45 -06:00

85 lines
1.1 KiB
Text

# Operator-identifying config and secrets (v0.3 split)
/data/config/local.yaml
/data/config/secrets/
/data/secrets/
.env
.env.local
.env.*
!.env.example
local.yaml
!local.yaml.example
# Python
__pycache__/
*.py[cod]
*$py.class
*.so
.Python
build/
develop-eggs/
dist/
downloads/
eggs/
.eggs/
/lib/
/lib64/
parts/
sdist/
var/
wheels/
*.egg-info/
.installed.cfg
*.egg
# Virtual environments
venv/
ENV/
# v0.5.5: anchor to repo root only -- bare `env/` matched meshai/env/ (the
# adapter package directory) and forced `git add -f` workarounds in 2.14/2.16.1.
/env/
.venv/
# IDE
.idea/
.vscode/
*.swp
*.swo
*~
# Project specific
config.yaml
*.db
*.sqlite
*.sqlite3
/data/
*.log
# Secrets
.env
*.pem
*.key
# Frontend build output (built in Docker via multi-stage)
meshai/dashboard/static/
# OS
.DS_Store
Thumbs.db
# Operator-identifying config and secrets (v0.3 split)
/data/config/local.yaml
/data/config/secrets/
/data/secrets/
.env
.env.local
.env.*
!.env.example
local.yaml
!local.yaml.example
data/*.sqlite
data/*.sqlite-wal
data/*.sqlite-shm
# Secrets (values live here, never committed)
/data/secrets/.env
data/secrets/.env
work/data/secrets/.env