Stop tracking .env and restore the ignore rules that 3455ad0 removed
3455ad0 deleted the .env patterns from .gitignore and committed a
real .env carrying a live ANTHROPIC_API_KEY. Two problems:
- The key is now in shared history and must be rotated; untracking
the file here stops the bleeding but does not un-publish it.
- That .env does not boot the API. It sets ANTHROPIC_API_KEY with no
MODEL_API_KEY, which config.go:503 refuses at startup — the same
guard that crash-looped krow-2 on 2026-09-07. Nothing in the
codebase reads ANTHROPIC_API_KEY; the MCP surface needs
OAUTH_ISSUER and MCP_RESOURCE, not a model credential.
The file stays on disk and is ignored again, along with
infrastructure/.env which the deleted pattern also covered.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PJvibeSc1JYXjatankqM1g
This commit is contained in:
3
.gitignore
vendored
3
.gitignore
vendored
@@ -1,5 +1,8 @@
|
||||
# Secrets and local configuration
|
||||
# A bare pattern matches at any depth, so this covers infrastructure/.env too.
|
||||
.env
|
||||
.env.local
|
||||
.env.*.local
|
||||
|
||||
# TLS material. The local-db overlay generates a self-signed pair inside the
|
||||
# postgres volume, but nothing stops someone dropping certs here by hand.
|
||||
|
||||
Reference in New Issue
Block a user