mirror of
https://github.com/zvx-echo6/meshai.git
synced 2026-08-26 17:31:34 +00:00
API keys/secrets now live in /data/secrets/.env (gitignored, never in config
YAML), while remaining fully editable from the dashboard. Config YAML holds
only ${VAR} references.
Backend:
- meshai/secrets_store.py: get_status (SET/NOT-SET, never values), set_secret,
delete_secret over /data/secrets/.env (resolved like load_config); authoritative
SECRET_FIELD_TO_ENV map (traffic→TOMTOM_API_KEY, firms→FIRMS_MAP_KEY,
roads511→ROADS511_API_KEY, wzdx→WZDX_API_KEY, smtp→SMTP_PASSWORD,
mesh_sources→MESHMONITOR_API_TOKEN) + backend-dependent llm_env_var
- dashboard/api/secrets_routes.py: GET /api/secrets (status only), PUT/DELETE
/api/secrets/{env_var} (validated, restart_required); registered in server.py
- config_loader: save_section preserves ${VAR} secret refs on section save
(never rejects them); EXPECTED_SECRETS += ROADS511_API_KEY, WZDX_API_KEY
- config.example.yaml + docker-entrypoint default config use ${VAR} refs;
first-run bootstraps /data/secrets/.env; .gitignore covers it
Frontend:
- components/ManagedSecret.tsx: masked, Set/Not-set badge, reveal, Save->PUT,
"restart required"; carries no config value so secrets never enter a section
save payload
- wired into Environment (tomtom/roads511/wzdx/firms), Config LLM tab
(env var by backend), Notifications (smtp)
Restart required after a secret change (env read at config-load). 11 store
tests; suite at 10-failure baseline (1714 passed).
Co-authored-by: Matt Johnson <mj@k7zvx.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
85 lines
1.1 KiB
Text
85 lines
1.1 KiB
Text
# Operator-identifying config and secrets (v0.3 split)
|
|
/data/config/local.yaml
|
|
/data/config/secrets/
|
|
/data/secrets/
|
|
.env
|
|
.env.local
|
|
.env.*
|
|
!.env.example
|
|
local.yaml
|
|
!local.yaml.example
|
|
# Python
|
|
__pycache__/
|
|
*.py[cod]
|
|
*$py.class
|
|
*.so
|
|
.Python
|
|
build/
|
|
develop-eggs/
|
|
dist/
|
|
downloads/
|
|
eggs/
|
|
.eggs/
|
|
/lib/
|
|
/lib64/
|
|
parts/
|
|
sdist/
|
|
var/
|
|
wheels/
|
|
*.egg-info/
|
|
.installed.cfg
|
|
*.egg
|
|
|
|
# Virtual environments
|
|
venv/
|
|
ENV/
|
|
# v0.5.5: anchor to repo root only -- bare `env/` matched meshai/env/ (the
|
|
# adapter package directory) and forced `git add -f` workarounds in 2.14/2.16.1.
|
|
/env/
|
|
.venv/
|
|
|
|
# IDE
|
|
.idea/
|
|
.vscode/
|
|
*.swp
|
|
*.swo
|
|
*~
|
|
|
|
# Project specific
|
|
config.yaml
|
|
*.db
|
|
*.sqlite
|
|
*.sqlite3
|
|
/data/
|
|
*.log
|
|
|
|
# Secrets
|
|
.env
|
|
*.pem
|
|
*.key
|
|
|
|
# Frontend build output (built in Docker via multi-stage)
|
|
meshai/dashboard/static/
|
|
|
|
|
|
# OS
|
|
.DS_Store
|
|
Thumbs.db
|
|
# Operator-identifying config and secrets (v0.3 split)
|
|
/data/config/local.yaml
|
|
/data/config/secrets/
|
|
/data/secrets/
|
|
.env
|
|
.env.local
|
|
.env.*
|
|
!.env.example
|
|
local.yaml
|
|
!local.yaml.example
|
|
data/*.sqlite
|
|
data/*.sqlite-wal
|
|
data/*.sqlite-shm
|
|
|
|
# Secrets (values live here, never committed)
|
|
/data/secrets/.env
|
|
data/secrets/.env
|
|
work/data/secrets/.env
|