From 7d83c16ec539bf5b45c228fda95d255638d13853 Mon Sep 17 00:00:00 2001 From: Suriyakumarvijayanayagam Date: Mon, 7 Sep 2026 12:33:47 +0530 Subject: [PATCH] Say plainly that a container has no keyless option Two comments in the compose model block were wrong in a way that mattered to the question "do we actually need a Groq key". The note about agent routes had lost its antecedent in the previous commit and dangled above MODEL_PROVIDER, appearing to describe provider selection. It belongs to MODEL_API_KEY. It was also only half true. It said an absent key is "a legitimate way to run this", which is correct outside production and impossible inside it: this stack defaults to APP_ENV=production, where validateModel refuses to start without a credential unless MODEL_BASE_URL is loopback. isLoopback accepts only localhost, 127.0.0.1 and ::1, so host.docker.internal does not qualify and no containerised deployment can take the keyless path. Reading the old comment, an operator would reasonably conclude they could leave the key empty and get a working API without Owliver. They get a container that will not boot. The endpoint count was stale too: routeRuns registers two, not three. routeOwliver's one endpoint does not touch s.agents and stays registered. Comments only; no behaviour change. vet clean, config and httpserver pass. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01PJvibeSc1JYXjatankqM1g --- infrastructure/docker-compose.yml | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/infrastructure/docker-compose.yml b/infrastructure/docker-compose.yml index e53312a..db793d7 100644 --- a/infrastructure/docker-compose.yml +++ b/infrastructure/docker-compose.yml @@ -88,10 +88,6 @@ services: <<: *database-env APP_ENV: ${APP_ENV:-production} LOG_LEVEL: ${LOG_LEVEL:-info} - # The agent run routes are not registered without this, so a deployment - # without it answers 404 on /agents/{id}/runs and reports three fewer - # endpoints on /version. Empty by default: absent is a working API - # without Owliver, which is a legitimate way to run this. # Provider selection. Empty MODEL_PROVIDER means openai — the only # implementation — and empty MODEL_BASE_URL means Groq. # @@ -101,6 +97,16 @@ services: # boots with no credential and fails every agent run. MODEL_PROVIDER: ${MODEL_PROVIDER:-} MODEL_BASE_URL: ${MODEL_BASE_URL:-} + # REQUIRED HERE. This stack defaults to APP_ENV=production, and config + # refuses to start in production without a credential unless MODEL_BASE_URL + # is loopback — which host.docker.internal is not, so there is no keyless + # option in a container. + # + # Outside production the key may be empty, and that is a real mode rather + # than a broken one: the agent routes are then not registered at all, so + # the deployment answers 404 on /agents/{id}/runs and reports two fewer + # endpoints on /version. An API without Owliver, saying so once at boot + # instead of once per request. MODEL_API_KEY: ${MODEL_API_KEY:-} MODEL_REASONING_EFFORT: ${MODEL_REASONING_EFFORT:-} ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-}