Skip to content

Document the key an operator cannot start beta without - #244

Merged
adamjohnwright merged 1 commit into
mainfrom
docs/beta-key-setup
Sep 18, 2026
Merged

adamjohnwright merged 1 commit into
mainfrom
docs/beta-key-setup

Conversation

@adamjohnwright

Copy link
Copy Markdown
Contributor

The key exchange happened today — the website generated a keypair, sent the public half, and it is installed and verified on beta. This closes the documentation gap that left behind.

The gap

.env.beta is gitignored, so deploy/beta/env.beta.template is the only tracked record of what the environment needs. It did not mention CALLER_TOKEN_PUBLIC_KEY_PATH — the one variable whose absence stops the container from starting. Neither did the README.

Someone setting beta up from these docs would have got a container that refuses to boot, with nothing in the documentation explaining why. The refusal is deliberate and well argued in the code; it was undiscoverable from the place an operator actually reads.

What changed

  • env.beta.template gains the variable, with why it exists and why a missing key takes /chat down too.
  • README.md gains a section covering where the public half comes from, that this host holds only the public half and therefore cannot mint, the 644 mode requirement (the image runs as appuser), and that rotation is a file write plus a restart.
  • It also says to delete any private half once a real key is installed. On the verifying side a signing key is pure liability — it quietly gives back exactly what choosing an asymmetric algorithm bought. That was this repo's own mistake until today.

State after the exchange

installed on beta the website's public key
our signing key deleted — no key that can mint for this path exists on this host
our old token now refused (this is the proof the swap took)
/chat HTTP 200, untouched
reversible previous public key backed up outside the repo

Full positive verification — a token they mint being accepted — needs their proxy, which does not exist yet. What is verified here is that the key changed, that the service is healthy, and that refusals still behave.

🤖 Generated with Claude Code

The key exchange happened today: the website generated a keypair, sent the public
half, and it is installed on beta. Neither deploy/beta/README.md nor
env.beta.template mentioned any of it, and .env.beta is gitignored -- so the
template was the only tracked record of what the environment needs, and it was
missing the one variable whose absence stops the container.

Someone setting beta up from these docs would have got a container that refuses
to start, with nothing in the documentation explaining why. The refusal is
deliberate and well argued in the code; it was undiscoverable from here.

The README now has the step that produces the file, says where the public half
comes from, and says to delete any private half once a real key is installed --
on the verifying side it is pure liability, which is the mistake this repo made
until today.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@adamjohnwright
adamjohnwright merged commit e1be359 into main Sep 18, 2026
10 checks passed
@adamjohnwright
adamjohnwright deleted the docs/beta-key-setup branch September 18, 2026 05:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant