mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 11:33:14 +00:00
fetch-config materialized only the FIRST page of Secrets Manager results: the AWS CLI does NOT auto-paginate batch-get-secret-value (the script's comment claiming it does was wrong; --no-cli-pager only disables the output pager, not API pagination). With 28 secret shells under open-swe-<env>/ the first page returned ~10 items, stranding the rest on later pages. Required secrets that landed past page 1 (DASHBOARD_JWT_SECRET, TOKEN_ENCRYPTION_KEY, LANGSMITH_API_KEY_PROD) were silently dropped, tripping the FAIL-FAST 'missing required var' guard and crash-looping open-swe.service. Follow NextToken across pages (new batch_get_secrets_tsv helper). Verified against the live open-swe-dev secrets: now loads all 5 populated secrets (was 2). Same per-record base64 / exact-prefix / accept_var / emit_var hardening — only the page loop is new. |
||
|---|---|---|
| .. | ||
| ami | ||
| seahaven | ||