diff --git a/deploy/seahaven/DEPLOYMENT.md b/deploy/seahaven/DEPLOYMENT.md index 2b4fe985..0a54a18c 100644 --- a/deploy/seahaven/DEPLOYMENT.md +++ b/deploy/seahaven/DEPLOYMENT.md @@ -218,10 +218,12 @@ on-box swapfile — the OOM-prone SPA build now runs in CI, not on the box. Model selection is **store-driven**, not env. The `team_settings/default` store doc wins (then per-user profile, then per-thread); `LLM_MODEL_ID` is only a seed-time fallback. Defaults seeded by `seed_store.sh`: -- builder: `anthropic:claude-opus-4-8` (effort `high`) -- reviewer (cross-family): `openai:gpt-5.5` (effort `high`) — `openai:gpt-4.1` is - **not** in this fork's `SUPPORTED_MODELS` (`agent/dashboard/options.py`); add it - there first if you need 4.1. +- builder: `bedrock_converse:us.anthropic.claude-opus-4-8` (effort `high`) +- reviewer: `bedrock_converse:us.anthropic.claude-opus-4-8` (effort `high`) — set + `SEED_REVIEWER_MODEL` (or change it in the UI) to a Fireworks model if you want a + cross-family reviewer. Only ids present in `SUPPORTED_MODELS` + (`agent/dashboard/options.py`) are valid; OpenAI/Google models were removed in the + Bedrock/Fireworks migration. - the `analyzer` graph is hardcoded to the code default and ignores team settings. ## Triggering diff --git a/deploy/seahaven/ROTATION.md b/deploy/seahaven/ROTATION.md index f895fcbd..38f7de45 100644 --- a/deploy/seahaven/ROTATION.md +++ b/deploy/seahaven/ROTATION.md @@ -68,7 +68,7 @@ sudo systemctl restart open-swe.service | **LINEAR_WEBHOOK_SECRET** | Linear webhook signature. Required in prod only when the Linear integration is wired (`LINEAR_API_KEY` present). Rotate in Linear + AWS together, restart. | | **SLACK_CLIENT_SECRET / GITHUB_APP_CLIENT_SECRET** | OAuth client secrets (dashboard login / Slack OAuth). Rotate in the provider console + AWS, restart. Existing dashboard sessions are JWT-signed by `DASHBOARD_JWT_SECRET`, not these, so they survive. | | **DASHBOARD_JWT_SECRET** | Signs dashboard session cookies. Rotating **invalidates all active sessions** (users re-login). Hard-required (RuntimeError if empty). No overlap list — single value. | -| **Model provider keys** (`ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, `GOOGLE_API_KEY`, `GROQ_API_KEY`, `FIREWORKS_API_KEY`) | Standard API-key rotation: issue new key, update AWS, restart, revoke old. The **active** provider keys (whatever `team_settings/default` seeds — currently `ANTHROPIC_API_KEY` + `OPENAI_API_KEY`) are fail-fast-required; keep `REQUIRED_PROVIDER_KEYS` in sync if you change the seeded models. | +| **Model provider keys** (`FIREWORKS_API_KEY`; legacy `ANTHROPIC_API_KEY` / `OPENAI_API_KEY` / `GOOGLE_API_KEY` / `GROQ_API_KEY`) | Standard API-key rotation: issue new key, update AWS, restart, revoke old. Bedrock (the seeded Claude builder + reviewer) authenticates via the **host IAM role — no API key**; the only fail-fast-required provider key is now `FIREWORKS_API_KEY` (fallback / subagents / any non-Claude model). Keep `REQUIRED_PROVIDER_KEYS` in sync if you change the seeded models. | | **LANGSMITH_API_KEY_PROD** | LangSmith key powering the `langsmith` sandbox (the only provider with working in-sandbox git/gh auth). Required when `SANDBOX_TYPE=langsmith` (fail-fast). Rotate in LangSmith + AWS, restart; existing sandboxes keep their already-injected proxy token until recycled. | | **SLACK_BOT_TOKEN / LINEAR_API_KEY / GITHUB_PAT / EXA_API_KEY / DAYTONA_API_KEY / RUNLOOP_API_KEY / CORRIDOR_* / USER_ID_API_KEY_MAP / X_SERVICE_AUTH_JWT_SECRET** | Plain API-token rotation: update AWS, restart, revoke old at the provider. None support an overlap list. | diff --git a/deploy/seahaven/fetch-config.sh b/deploy/seahaven/fetch-config.sh index bf82cad1..50e8b214 100755 --- a/deploy/seahaven/fetch-config.sh +++ b/deploy/seahaven/fetch-config.sh @@ -269,9 +269,10 @@ required=( # deployment-validation env (boot/health/boundary), not a live-triggered agent. # Active model-provider key(s): model selection is store-driven (team_settings), -# so fetch-config cannot infer it from .env. Default to the seeded cross-family -# pair (anthropic builder + openai reviewer). Override with a comma list. -IFS=',' read -r -a provider_keys <<<"${REQUIRED_PROVIDER_KEYS:-ANTHROPIC_API_KEY,OPENAI_API_KEY}" +# so fetch-config cannot infer it from .env. Bedrock (Claude builder + reviewer) +# authenticates via the host IAM role — no API key; Fireworks (fallback / subagents / +# any non-Claude model) needs its key. Override with a comma list if the active models change. +IFS=',' read -r -a provider_keys <<<"${REQUIRED_PROVIDER_KEYS:-FIREWORKS_API_KEY}" for k in "${provider_keys[@]}"; do k="${k//[[:space:]]/}" [ -n "$k" ] && required+=("$k") diff --git a/deploy/seahaven/put-config.sh b/deploy/seahaven/put-config.sh index 76c9d722..f75194d2 100755 --- a/deploy/seahaven/put-config.sh +++ b/deploy/seahaven/put-config.sh @@ -104,7 +104,7 @@ put_secret CORRIDOR_MCP_TOKEN # optional — Corridor MCP (alt name) put_secret CORRIDOR_TOKEN # optional — Corridor MCP (alt name) put_secret DAYTONA_API_KEY # only if SANDBOX_TYPE=daytona put_secret EXA_API_KEY # optional — Exa web search -put_secret FIREWORKS_API_KEY # only if a fireworks: model is used +put_secret FIREWORKS_API_KEY # active non-Claude key (fallback/subagents); Bedrock uses the host IAM role put_secret GITHUB_PAT # optional — PAT fallback put_secret GOOGLE_API_KEY # only if a google_genai: model is used put_secret GROQ_API_KEY # only if a groq: model is used diff --git a/deploy/seahaven/seed_store.sh b/deploy/seahaven/seed_store.sh index e3765917..dfe1a416 100755 --- a/deploy/seahaven/seed_store.sh +++ b/deploy/seahaven/seed_store.sh @@ -77,9 +77,9 @@ pick() { # pick DEFAULT OVERRIDE_VALUE FILE_KEY... # local server; OPENSWE_PORT may override the port but never the host. BASE="http://127.0.0.1:${OPENSWE_PORT:-2024}" -AGENT_MODEL="$(pick 'anthropic:claude-opus-4-8' "${OPENSWE_AGENT_MODEL:-}" SEED_AGENT_MODEL LLM_MODEL_ID)" +AGENT_MODEL="$(pick 'bedrock_converse:us.anthropic.claude-opus-4-8' "${OPENSWE_AGENT_MODEL:-}" SEED_AGENT_MODEL LLM_MODEL_ID)" AGENT_EFFORT="$(pick 'high' "${OPENSWE_AGENT_EFFORT:-}" SEED_AGENT_EFFORT)" -REVIEWER_MODEL="$(pick 'openai:gpt-5.5' "${OPENSWE_REVIEWER_MODEL:-}" SEED_REVIEWER_MODEL)" +REVIEWER_MODEL="$(pick 'bedrock_converse:us.anthropic.claude-opus-4-8' "${OPENSWE_REVIEWER_MODEL:-}" SEED_REVIEWER_MODEL)" REVIEWER_EFFORT="$(pick 'high' "${OPENSWE_REVIEWER_EFFORT:-}" SEED_REVIEWER_EFFORT)" # default_repo = owner/name from AWS config (DEFAULT_REPO_OWNER is hard-pinned