open-swe/deploy/seahaven
Adam Moussa a2877d46ff
fix: paginate batch-get-secret-value in fetch-config (secrets dropped past page 1) (#24)
fetch-config materialized only the FIRST page of Secrets Manager results: the AWS CLI
does NOT auto-paginate batch-get-secret-value (the script's comment claiming it does
was wrong; --no-cli-pager only disables the output pager, not API pagination). With 28
secret shells under open-swe-<env>/ the first page returned ~10 items, stranding the
rest on later pages. Required secrets that landed past page 1 (DASHBOARD_JWT_SECRET,
TOKEN_ENCRYPTION_KEY, LANGSMITH_API_KEY_PROD) were silently dropped, tripping the
FAIL-FAST 'missing required var' guard and crash-looping open-swe.service.

Follow NextToken across pages (new batch_get_secrets_tsv helper). Verified against the
live open-swe-dev secrets: now loads all 5 populated secrets (was 2). Same per-record
base64 / exact-prefix / accept_var / emit_var hardening — only the page loop is new.
2026-06-26 19:55:01 -04:00
..
aegra ci: promote dev → prod via fast-forward (not force-push from main) (#2) 2026-06-26 11:20:10 -04:00
nginx feat(deploy): add Sea Haven self-hosted deployment capture 2026-06-25 17:28:34 -04:00
systemd feat(deploy): add Sea Haven self-hosted deployment capture 2026-06-25 17:28:34 -04:00
DEPLOYMENT.md feat(deploy): AWS-sourced fetch-config + seed_store + rotation docs (PR#7) (#8) 2026-06-26 15:06:41 -04:00
fetch-config.sh fix: paginate batch-get-secret-value in fetch-config (secrets dropped past page 1) (#24) 2026-06-26 19:55:01 -04:00
put-config.sh feat: Secrets Manager + SSM config store for open-swe (T11) (#10) 2026-06-26 16:07:23 -04:00
ROTATION.md feat(deploy): AWS-sourced fetch-config + seed_store + rotation docs (PR#7) (#8) 2026-06-26 15:06:41 -04:00
seed_store.sh feat(deploy): AWS-sourced fetch-config + seed_store + rotation docs (PR#7) (#8) 2026-06-26 15:06:41 -04:00