diff --git a/stacks/searxng/conf/searxng-settings.yml b/stacks/searxng/conf/searxng-settings.yml index 9bc1b9c..1db46ab 100644 --- a/stacks/searxng/conf/searxng-settings.yml +++ b/stacks/searxng/conf/searxng-settings.yml @@ -64,14 +64,26 @@ use_default_settings: # hardcode). A GLM web-search engine is possible as a custom JSON engine but # needs a z.ai/bigmodel search key — not in the vault as of today. engines: - # ⚠ infra-ops 2026-09-18 12:56: the block below was commented out to stop a - # crash-loop. This searxng build has no !ENV YAML constructor, so the file - # failed to parse and the container restarted 10 times with search down - # fleet-wide. Original preserved at searxng-settings.yml.inflight-20260918-1252. - # Inline the key or load it another way; !ENV is not supported here. - # - name: braveapi - # api_key: !ENV SEARXNG_BRAVE_API_KEY - # inactive: false + # ⚠ THE KEY BELOW IS COMMITTED ON PURPOSE. Operator decision, 2026-09-18: + # this is a free-tier Brave Search API key on a rate-limited service of + # marginal value — "if the service is useless, so is the key" — so it is not + # worth the machinery that keeping it out of git would cost. Do not treat + # this as licence for other credentials; everything else goes in the vault + # (this key is also at nh3-docker/searxng-brave-api-key). + # + # ⚠ It cannot be un-committed. Rotation means issuing a NEW key at Brave and + # replacing this line, never rewriting history — the repo is shared and + # other sessions commit to it. + # + # An earlier attempt used `api_key: !ENV SEARXNG_BRAVE_API_KEY`. This build + # has no !ENV YAML constructor, so the file failed to parse and the container + # crash-looped ten times with search down fleet-wide. There is no env-var + # path into this file: the loader reads only SEARXNG_SETTINGS_PATH, and the + # entrypoint substitutes only `ultrasecretkey`. Literal or nothing. + - name: braveapi + api_key: BSAa55OlyBPDjHcvyRiOcBl5USayGXb + disabled: false + inactive: false - name: marginalia api_key: public disabled: false