docs(fleettools): autoload for Codex and Grok, and a vaulted gateway key
Codex reads a global AGENTS.md from CODEX_HOME; Grok always scans ~/.grok/rules/ and loads every *.md in it regardless of name. Both were empty, so AGENT-BOOTSTRAP.md is symlinked into each rather than copied — one file, three agent families, no drift surface. The bootstrap is a pointer, not a second index: it names ~/FLEETTOOLS.md, gives the three live-inventory endpoints, and inlines only the rules that must hold even if the agent never opens anything else — attribution to Vuong Hoang, no committed secrets, the operator owns architectural calls, n=1 is not a measurement, and absence of a signal is not a safe reading of it. The shared all-agents LiteLLM key was single-copy in ~/.claude/CLAUDE.md and is now also in the vault at litellm/all-agents-shared-key, per the standing directive that durable credentials never live in one place. It stays inline in CLAUDE.md too, since every session needs it and a vault round-trip measured over two minutes. Namespace is service-scoped rather than host-prefixed because the key is fleet-wide, matching the existing att/fortigate/headscale/unifi/worldtree entries.
This commit is contained in:
@@ -19,7 +19,7 @@ The gateway **401s without a virtual API key**. Three tiers:
|
||||
|
||||
| key | where | reach |
|
||||
|---|---|---|
|
||||
| shared all-agents (`all-agents-local`) | `~/.claude/CLAUDE.md` § Global tools | **every** model, paid passthroughs included |
|
||||
| shared all-agents (`all-agents-local`) | `secret get litellm/all-agents-shared-key`, also inline in `~/.claude/CLAUDE.md` § Global tools | **every** model, paid passthroughs included |
|
||||
| infra-ops admin | `~/.config/litellm/infra-ops-key` (0600) | admin operations |
|
||||
| project-scoped | request from infra-ops via althing | isolated, auditable spend |
|
||||
|
||||
|
||||
Reference in New Issue
Block a user