feat(arbo): disable ENGINE_TOKEN bearer auth on prod (WireGuard = boundary)

Operator decision 2026-06-13 (relayed by comfy-dev, confirmed in-session):
turn off the prod arbo engine's bearer auth and rely on the WireGuard
perimeter. Reverses ADR-0001's open-auth-hole-closed posture (comfy-dev owns
the ADR update on the vh/arbo side).

The app's protected-gate no-ops only when ENGINE_TOKEN is ABSENT — an empty
string still gates (verified: ENGINE_TOKEN="" -> /workflows 401). So both
inject paths are removed: the compose environment line is commented out and
the .env line deleted on the host. Result: tokenless GET /workflows 200 (was
401), matching the dev engine. Original token preserved in the host's
.env.pre-auth-off.bak for re-enable.

playbooks/arbo-disable-engine-token.yaml captures the reversible procedure.
This commit is contained in:
vh
2026-06-13 14:05:07 -07:00
parent f32c6ddaab
commit db97899037
4 changed files with 88 additions and 7 deletions
+7 -3
View File
@@ -16,9 +16,13 @@ ARBO_GID=1000
ARBO_CATALOG_DIR=/worktank/arbo/repo
# ── Secrets (DO NOT COMMIT REAL VALUES) ──────────────────────────────
# ENGINE_TOKEN: a real bearer token — auth is OPEN until this is set.
# Mint a fresh one: openssl rand -hex 32
ENGINE_TOKEN=
# ENGINE_TOKEN: bearer auth is intentionally OFF (operator decision 2026-06-13,
# WireGuard = the boundary). Leave it UNSET — the protected-gate no-ops only
# when the var is ABSENT (an empty `ENGINE_TOKEN=` still gates), and the compose
# injection is commented out to match. To re-lock: un-comment the compose line
# `- ENGINE_TOKEN=${ENGINE_TOKEN}`, mint a bearer (`openssl rand -hex 32`), set
# it below, `compose up -d`.
# ENGINE_TOKEN=
# GRANITE_KEY: the LiteLLM virtual key scoped to arbo. The 'arbo-prompt-enhance'
# vkey (comfy-dev, issued 2026-06-09) is extended to reach BOTH granite-4.1-8b