Board minutes #62 Decision 2 (server-26#64), due 2026-08-31. CTO draft #60 finding 1 and CISO draft #61 finding 3 reached this independently. GET/PUT /admin/features accepted only a Firebase admin token, so the unattended runbook had no headless path and SSHed into the c2-core container to write config/ai_features with the admin SDK. Moving a platform-wide AI cost switch required a full container shell, and set_flags() wrote no audit entry either way, so a flag flip was unattributable however it happened. - New agent_service_key (AGENT_SERVICE_KEY), deliberately separate from the Discord bot's service_key. Sharing one key would collapse two principals into a single unattributable identity in every log line, and the bot has no business flipping AI flags regardless. - require_agent_key_or_admin accepts the agent key or a Firebase admin, and rejects the Discord key. The "key is configured" guard is load-bearing: compare_digest("", "") is a match, so a deployment that never set the key would otherwise accept an empty credential. - set_flags() writes an audit_log entry with before/after values and the actor, wrapped so an audit failure cannot lose the flag write or 500 the route. - Cascade helper sets the global doc and every system carrying an ai_flags override in one call. A global False already beats everything, but a system False beats a global True, so turning AI *on* could half-apply and leave a radio system hot after shutoff. It scans for the override rather than hardcoding the two known system IDs, so a new system cannot silently defeat it. - cascade defaults to False. PUT /systems/{id}/ai-flags and the AiFlagsPanel toggle mean a per-system override is deliberate operator intent; cascading by default would erase it on any unrelated global flip. The runbook opts in. Issue items 5 and 6 (retiring the SSH path from drb-worksession.md) are NOT done here and the runbook is untouched. The credential does not exist in production yet, so the SSH path is still the only one that works; retiring it now would break the next unattended run. Owner activation is recorded on #64. Tests 273 -> 289. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
47 lines
2.2 KiB
Bash
47 lines
2.2 KiB
Bash
# drb-c2-core environment — Managed by Ansible. Do not edit manually.
|
|
|
|
MQTT_BROKER=mosquitto
|
|
MQTT_PORT=1883
|
|
MQTT_USER={{ vault_mqtt_c2_user }}
|
|
MQTT_PASS={{ vault_mqtt_c2_pass }}
|
|
|
|
# Same value as mosquitto's MOSQUITTO_DYNSEC_PASSWORD (root.env.j2) — lets
|
|
# c2-core log in as the dynsec plugin's built-in "admin" client to
|
|
# administer node credentials. See app/internal/dynsec.py.
|
|
MQTT_DYNSEC_ADMIN_PASS={{ vault_mqtt_dynsec_admin_pass }}
|
|
|
|
# No GCP_CREDENTIALS_PATH — the VM uses Application Default Credentials
|
|
# via the GCE metadata server. The Terraform IAM bindings grant the required roles.
|
|
# NOTE: because there is no service-account key file here, c2-core cannot mint
|
|
# GCS *signed* URLs. Call audio is therefore served through c2-core's own
|
|
# /media route (app/routers/media.py) rather than direct-from-bucket links.
|
|
FIRESTORE_DATABASE={{ vault_firestore_database }}
|
|
GCS_BUCKET={{ vault_gcs_bucket }}
|
|
|
|
# Absolute origin for call-audio playback links. The browser fetches <audio src>
|
|
# directly, so a relative path would resolve against the frontend origin
|
|
# (https://{{ domain }}) instead of the API's.
|
|
PUBLIC_API_URL=https://api.{{ domain }}
|
|
|
|
OPENAI_API_KEY={{ vault_openai_api_key }}
|
|
GOOGLE_MAPS_API_KEY={{ vault_google_maps_api_key }}
|
|
GEMINI_API_KEY={{ vault_gemini_api_key }}
|
|
|
|
SERVICE_KEY={{ vault_service_key }}
|
|
ENROLLMENT_TOKEN={{ vault_enrollment_token }}
|
|
|
|
# Agent/automation key for the unattended work session's headless routes
|
|
# (GET/PUT /admin/features). MUST NOT equal vault_service_key: that one is the
|
|
# Discord bot's, and one shared value would make the bot and the agent the same
|
|
# unattributable principal in audit_log (server-26#64). default('') so a vault
|
|
# that predates this key still templates instead of failing the play; blank
|
|
# just leaves the agent path closed.
|
|
AGENT_SERVICE_KEY={{ vault_agent_service_key | default('') }}
|
|
|
|
# Bare domain, not app.<domain>: the frontend is served on {{ domain }} itself
|
|
# (see Caddyfile.j2 — only api. and the bare name have DNS records). This said
|
|
# app.{{ domain }} while the browser origin was https://{{ domain }}, so every
|
|
# frontend call to the API would have failed CORS. If the frontend ever moves
|
|
# to app.{{ domain }}, change this at the same time.
|
|
CORS_ORIGINS=["https://{{ domain }}"]
|