skaldsong: align env-var contract with app reality (pre-first-deploy)

skaldsong-dev surfaced three contract corrections before the first
deploy:

- WORLDTREE_TOKEN (outbound HTTP Bearer) was missing — separate code
  path from SKALDSONG_BIFROST_JWT_KEY (inbound HS256 verify) but
  same secret value.
- WORLDTREE_BASE_URL replaces SKALDSONG_WORLDTREE_API_URL (the
  former is what the app actually reads).
- SKALDSONG_HOST_WIZARD_AGENT_ID was missing entirely — must pin to
  skaldsong:wizard-v2 to inherit the existing Worldtree agent slot;
  blank would burn another slot of the 50-per-key Heimdall quota.
This commit is contained in:
vh
2026-05-18 23:10:37 -07:00
parent 55e2e836a8
commit 8a4276d6b5
3 changed files with 31 additions and 8 deletions
+11 -3
View File
@@ -39,9 +39,17 @@ SKALDSONG_BIFROST_JWT_KEY=
# Coordinated update with worldtree-dev required if host:port changes.
SKALDSONG_HOST_BIFROST_ENDPOINT_URL=http://10.250.50.70:8300
# URL skaldsong uses to call Worldtree's conversation API. From
# ana-docker, corviduo-dev's IP:port LAN-direct.
SKALDSONG_WORLDTREE_API_URL=http://10.250.50.152:8080
# Worldtree API client — outbound. Same Bearer as
# SKALDSONG_BIFROST_JWT_KEY (different code path consumes it).
WORLDTREE_TOKEN=
WORLDTREE_BASE_URL=http://10.250.50.152:8080
# Wizard agent ID on Worldtree. MUST be pinned to the existing slot
# (skaldsong:wizard-v2) — blank would POST /agents/define and burn a
# slot of the 50-agent-per-key quota. Heimdall scopes agent_id to
# user_id, so this matches the agent defined from skaldsong-dev's
# prior nh3-dev hand-launch.
SKALDSONG_HOST_WIZARD_AGENT_ID=skaldsong:wizard-v2
# CORS — comma-separated origins. Include the SPA's public hostname AND
# any dev origins still in rotation.