secert updated

This commit is contained in:
2026-09-24 17:20:04 +05:30
parent 299871b820
commit 00317a00d8
11 changed files with 517 additions and 81 deletions

View File

@@ -245,20 +245,59 @@ func (a AssistantConfig) ModelFor(tier string) string {
return a.Balanced
}
// What Nearle Buddy runs on unless a deployment says otherwise.
//
// These are in the code rather than in the environment because they are not
// secrets and not deployment-specific — they are what this product uses. Every
// variable that has one right answer is a variable somebody has to remember,
// get past a platform's UI, and then re-enter on the next environment; three of
// the four were exactly that, and the assistant sat switched off for days
// because one of them had not been typed.
//
// The API key is the one that genuinely varies and genuinely cannot live here.
const (
defaultAssistantProvider = "openai"
defaultAssistantBaseURL = "https://api.groq.com/openai/v1"
defaultAssistantModel = "openai/gpt-oss-120b"
)
// assistantProvider reads the provider, defaulting to the one shape this
// server speaks.
//
// A deployment that names a model and a key has said what it wants; making it
// also name a protocol it has no choice about is a variable that exists only to
// be forgotten.
// Every endpoint here is OpenAI-compatible — Groq, Ollama, Together and OpenAI
// itself — so the base URL is what actually distinguishes them. Naming a
// protocol you have no choice about is a variable that exists only to be
// forgotten.
func assistantProvider() string {
if named := strings.ToLower(strings.TrimSpace(env("ASSISTANT_PROVIDER", ""))); named != "" {
return named
}
if strings.TrimSpace(env("ASSISTANT_MODEL_BALANCED", env("ASSISTANT_MODEL", ""))) != "" {
return "openai"
return defaultAssistantProvider
}
// AssistantFromEnv reads the assistant's settings, defaults and all.
//
// Exported and used by `Load` rather than written inline there, because the
// live tests need the SAME reading. They used to build this struct by hand from
// `os.Getenv`, which meant they skipped silently the moment a default was
// introduced — they were testing a configuration production no longer uses,
// and the one time that mattered was the day the provider stopped being
// required and nothing noticed.
//
// Three of the four fields have one right answer and come from the constants
// above. The key varies between deployments and is the only one that cannot
// live in this repository.
func AssistantFromEnv() AssistantConfig {
return AssistantConfig{
Provider: assistantProvider(),
BaseURL: env("ASSISTANT_BASE_URL", defaultAssistantBaseURL),
APIKey: env("ASSISTANT_API_KEY", ""),
Fast: env("ASSISTANT_MODEL_FAST", ""),
// ASSISTANT_MODEL alone still sets every tier, for a deployment that
// wants one model everywhere but not this one.
Balanced: env("ASSISTANT_MODEL_BALANCED", env("ASSISTANT_MODEL", defaultAssistantModel)),
Deep: env("ASSISTANT_MODEL_DEEP", ""),
}
return ""
}
// IsProduction is true under APP_ENV=production.
@@ -317,20 +356,7 @@ func Load() (*Config, error) {
BaseURL: env("EMBEDDING_BASE_URL", ""),
},
Assistant: AssistantConfig{
// Defaults to "openai" when a model is named, because every endpoint
// this speaks is OpenAI-compatible and the base URL is what actually
// distinguishes them. One less variable to set, and one less way to
// have the assistant silently off.
Provider: assistantProvider(),
BaseURL: env("ASSISTANT_BASE_URL", ""),
APIKey: env("ASSISTANT_API_KEY", ""),
Fast: env("ASSISTANT_MODEL_FAST", ""),
// ASSISTANT_MODEL alone sets every tier, for a deployment that has
// not thought about tiers yet.
Balanced: env("ASSISTANT_MODEL_BALANCED", env("ASSISTANT_MODEL", "")),
Deep: env("ASSISTANT_MODEL_DEEP", ""),
},
Assistant: AssistantFromEnv(),
POSTokenSecret: env("POS_TOKEN_SECRET", ""),
JWTSecret: env("JWT_SECRET_KEY", ""),