mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
fix(deploy): seed Bedrock/Fireworks models, not the dropped anthropic:/openai: ids
Model selection is store-driven, so seed_store.sh's team_settings/default seed is what runs in prod. It still seeded the removed providers, which would fail at runtime after the migration: - agent/builder: anthropic:claude-opus-4-8 -> bedrock_converse:us.anthropic.claude-opus-4-8 - reviewer: openai:gpt-5.5 (dropped) -> bedrock_converse:us.anthropic.claude-opus-4-8 (set SEED_REVIEWER_MODEL to a Fireworks model for a cross-family reviewer) - fetch-config REQUIRED_PROVIDER_KEYS default ANTHROPIC_API_KEY,OPENAI_API_KEY -> FIREWORKS_API_KEY (Bedrock auths via host IAM role; dropping the old keys would otherwise fail-fast at boot) - docs (DEPLOYMENT/ROTATION/put-config) updated to match. Surfaced by the cross-family review + verified against deploy/.
This commit is contained in:
parent
3a10830e90
commit
f3febed06c
5 changed files with 14 additions and 11 deletions
|
|
@ -218,10 +218,12 @@ on-box swapfile — the OOM-prone SPA build now runs in CI, not on the box.
|
|||
Model selection is **store-driven**, not env. The `team_settings/default` store
|
||||
doc wins (then per-user profile, then per-thread); `LLM_MODEL_ID` is only a
|
||||
seed-time fallback. Defaults seeded by `seed_store.sh`:
|
||||
- builder: `anthropic:claude-opus-4-8` (effort `high`)
|
||||
- reviewer (cross-family): `openai:gpt-5.5` (effort `high`) — `openai:gpt-4.1` is
|
||||
**not** in this fork's `SUPPORTED_MODELS` (`agent/dashboard/options.py`); add it
|
||||
there first if you need 4.1.
|
||||
- builder: `bedrock_converse:us.anthropic.claude-opus-4-8` (effort `high`)
|
||||
- reviewer: `bedrock_converse:us.anthropic.claude-opus-4-8` (effort `high`) — set
|
||||
`SEED_REVIEWER_MODEL` (or change it in the UI) to a Fireworks model if you want a
|
||||
cross-family reviewer. Only ids present in `SUPPORTED_MODELS`
|
||||
(`agent/dashboard/options.py`) are valid; OpenAI/Google models were removed in the
|
||||
Bedrock/Fireworks migration.
|
||||
- the `analyzer` graph is hardcoded to the code default and ignores team settings.
|
||||
|
||||
## Triggering
|
||||
|
|
|
|||
|
|
@ -68,7 +68,7 @@ sudo systemctl restart open-swe.service
|
|||
| **LINEAR_WEBHOOK_SECRET** | Linear webhook signature. Required in prod only when the Linear integration is wired (`LINEAR_API_KEY` present). Rotate in Linear + AWS together, restart. |
|
||||
| **SLACK_CLIENT_SECRET / GITHUB_APP_CLIENT_SECRET** | OAuth client secrets (dashboard login / Slack OAuth). Rotate in the provider console + AWS, restart. Existing dashboard sessions are JWT-signed by `DASHBOARD_JWT_SECRET`, not these, so they survive. |
|
||||
| **DASHBOARD_JWT_SECRET** | Signs dashboard session cookies. Rotating **invalidates all active sessions** (users re-login). Hard-required (RuntimeError if empty). No overlap list — single value. |
|
||||
| **Model provider keys** (`ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, `GOOGLE_API_KEY`, `GROQ_API_KEY`, `FIREWORKS_API_KEY`) | Standard API-key rotation: issue new key, update AWS, restart, revoke old. The **active** provider keys (whatever `team_settings/default` seeds — currently `ANTHROPIC_API_KEY` + `OPENAI_API_KEY`) are fail-fast-required; keep `REQUIRED_PROVIDER_KEYS` in sync if you change the seeded models. |
|
||||
| **Model provider keys** (`FIREWORKS_API_KEY`; legacy `ANTHROPIC_API_KEY` / `OPENAI_API_KEY` / `GOOGLE_API_KEY` / `GROQ_API_KEY`) | Standard API-key rotation: issue new key, update AWS, restart, revoke old. Bedrock (the seeded Claude builder + reviewer) authenticates via the **host IAM role — no API key**; the only fail-fast-required provider key is now `FIREWORKS_API_KEY` (fallback / subagents / any non-Claude model). Keep `REQUIRED_PROVIDER_KEYS` in sync if you change the seeded models. |
|
||||
| **LANGSMITH_API_KEY_PROD** | LangSmith key powering the `langsmith` sandbox (the only provider with working in-sandbox git/gh auth). Required when `SANDBOX_TYPE=langsmith` (fail-fast). Rotate in LangSmith + AWS, restart; existing sandboxes keep their already-injected proxy token until recycled. |
|
||||
| **SLACK_BOT_TOKEN / LINEAR_API_KEY / GITHUB_PAT / EXA_API_KEY / DAYTONA_API_KEY / RUNLOOP_API_KEY / CORRIDOR_* / USER_ID_API_KEY_MAP / X_SERVICE_AUTH_JWT_SECRET** | Plain API-token rotation: update AWS, restart, revoke old at the provider. None support an overlap list. |
|
||||
|
||||
|
|
|
|||
|
|
@ -269,9 +269,10 @@ required=(
|
|||
# deployment-validation env (boot/health/boundary), not a live-triggered agent.
|
||||
|
||||
# Active model-provider key(s): model selection is store-driven (team_settings),
|
||||
# so fetch-config cannot infer it from .env. Default to the seeded cross-family
|
||||
# pair (anthropic builder + openai reviewer). Override with a comma list.
|
||||
IFS=',' read -r -a provider_keys <<<"${REQUIRED_PROVIDER_KEYS:-ANTHROPIC_API_KEY,OPENAI_API_KEY}"
|
||||
# so fetch-config cannot infer it from .env. Bedrock (Claude builder + reviewer)
|
||||
# authenticates via the host IAM role — no API key; Fireworks (fallback / subagents /
|
||||
# any non-Claude model) needs its key. Override with a comma list if the active models change.
|
||||
IFS=',' read -r -a provider_keys <<<"${REQUIRED_PROVIDER_KEYS:-FIREWORKS_API_KEY}"
|
||||
for k in "${provider_keys[@]}"; do
|
||||
k="${k//[[:space:]]/}"
|
||||
[ -n "$k" ] && required+=("$k")
|
||||
|
|
|
|||
|
|
@ -104,7 +104,7 @@ put_secret CORRIDOR_MCP_TOKEN # optional — Corridor MCP (alt name)
|
|||
put_secret CORRIDOR_TOKEN # optional — Corridor MCP (alt name)
|
||||
put_secret DAYTONA_API_KEY # only if SANDBOX_TYPE=daytona
|
||||
put_secret EXA_API_KEY # optional — Exa web search
|
||||
put_secret FIREWORKS_API_KEY # only if a fireworks: model is used
|
||||
put_secret FIREWORKS_API_KEY # active non-Claude key (fallback/subagents); Bedrock uses the host IAM role
|
||||
put_secret GITHUB_PAT # optional — PAT fallback
|
||||
put_secret GOOGLE_API_KEY # only if a google_genai: model is used
|
||||
put_secret GROQ_API_KEY # only if a groq: model is used
|
||||
|
|
|
|||
|
|
@ -77,9 +77,9 @@ pick() { # pick DEFAULT OVERRIDE_VALUE FILE_KEY...
|
|||
# local server; OPENSWE_PORT may override the port but never the host.
|
||||
BASE="http://127.0.0.1:${OPENSWE_PORT:-2024}"
|
||||
|
||||
AGENT_MODEL="$(pick 'anthropic:claude-opus-4-8' "${OPENSWE_AGENT_MODEL:-}" SEED_AGENT_MODEL LLM_MODEL_ID)"
|
||||
AGENT_MODEL="$(pick 'bedrock_converse:us.anthropic.claude-opus-4-8' "${OPENSWE_AGENT_MODEL:-}" SEED_AGENT_MODEL LLM_MODEL_ID)"
|
||||
AGENT_EFFORT="$(pick 'high' "${OPENSWE_AGENT_EFFORT:-}" SEED_AGENT_EFFORT)"
|
||||
REVIEWER_MODEL="$(pick 'openai:gpt-5.5' "${OPENSWE_REVIEWER_MODEL:-}" SEED_REVIEWER_MODEL)"
|
||||
REVIEWER_MODEL="$(pick 'bedrock_converse:us.anthropic.claude-opus-4-8' "${OPENSWE_REVIEWER_MODEL:-}" SEED_REVIEWER_MODEL)"
|
||||
REVIEWER_EFFORT="$(pick 'high' "${OPENSWE_REVIEWER_EFFORT:-}" SEED_REVIEWER_EFFORT)"
|
||||
|
||||
# default_repo = owner/name from AWS config (DEFAULT_REPO_OWNER is hard-pinned
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue