Repository navigation
Document the key an operator cannot start beta without - #244
Merged
Merged
Conversation
The key exchange happened today: the website generated a keypair, sent the public half, and it is installed on beta. Neither deploy/beta/README.md nor env.beta.template mentioned any of it, and .env.beta is gitignored -- so the template was the only tracked record of what the environment needs, and it was missing the one variable whose absence stops the container. Someone setting beta up from these docs would have got a container that refuses to start, with nothing in the documentation explaining why. The refusal is deliberate and well argued in the code; it was undiscoverable from here. The README now has the step that produces the file, says where the public half comes from, and says to delete any private half once a real key is installed -- on the verifying side it is pure liability, which is the mistake this repo made until today. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The key exchange happened today — the website generated a keypair, sent the public half, and it is installed and verified on beta. This closes the documentation gap that left behind.
The gap
.env.betais gitignored, sodeploy/beta/env.beta.templateis the only tracked record of what the environment needs. It did not mentionCALLER_TOKEN_PUBLIC_KEY_PATH— the one variable whose absence stops the container from starting. Neither did the README.Someone setting beta up from these docs would have got a container that refuses to boot, with nothing in the documentation explaining why. The refusal is deliberate and well argued in the code; it was undiscoverable from the place an operator actually reads.
What changed
env.beta.templategains the variable, with why it exists and why a missing key takes/chatdown too.README.mdgains a section covering where the public half comes from, that this host holds only the public half and therefore cannot mint, the 644 mode requirement (the image runs asappuser), and that rotation is a file write plus a restart.State after the exchange
refused(this is the proof the swap took)/chatFull positive verification — a token they mint being accepted — needs their proxy, which does not exist yet. What is verified here is that the key changed, that the service is healthy, and that refusals still behave.
🤖 Generated with Claude Code