3455ad0 deleted the .env patterns from .gitignore and committed a
real .env carrying a live ANTHROPIC_API_KEY. Two problems:
- The key is now in shared history and must be rotated; untracking
the file here stops the bleeding but does not un-publish it.
- That .env does not boot the API. It sets ANTHROPIC_API_KEY with no
MODEL_API_KEY, which config.go:503 refuses at startup — the same
guard that crash-looped krow-2 on 2026-09-07. Nothing in the
codebase reads ANTHROPIC_API_KEY; the MCP surface needs
OAUTH_ISSUER and MCP_RESOURCE, not a model credential.
The file stays on disk and is ignored again, along with
infrastructure/.env which the deleted pattern also covered.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PJvibeSc1JYXjatankqM1g
32 lines
756 B
Plaintext
32 lines
756 B
Plaintext
# Secrets and local configuration
|
|
# A bare pattern matches at any depth, so this covers infrastructure/.env too.
|
|
.env
|
|
.env.local
|
|
.env.*.local
|
|
|
|
# TLS material. The local-db overlay generates a self-signed pair inside the
|
|
# postgres volume, but nothing stops someone dropping certs here by hand.
|
|
*.pem
|
|
*.key
|
|
*.crt
|
|
|
|
# Structural snapshots taken before destructive migrations
|
|
krowdb_public_snapshot_*.sql
|
|
|
|
# Go build output
|
|
/go-api/bin/
|
|
*.test
|
|
*.out
|
|
|
|
# Editor / OS
|
|
.DS_Store
|
|
.idea/
|
|
.vscode/
|
|
|
|
# Filled-in Kubernetes secret (the .example is the committed template)
|
|
infrastructure/k8s/10-secret.yaml
|
|
|
|
# Database exports. Real tenant data — password hashes, personal details.
|
|
# Generated by `make export-data`; move it over scp, never through git.
|
|
seed/exports/
|