Skip to content

feat(ci): Add provider API key validation to env_check.sh - #591

Merged
POWERFULMOVES merged 1 commit into
PMOVES.AI-Edition-Hardenedfrom
fix/api-key-validation
Feb 7, 2026
Merged

POWERFULMOVES merged 1 commit into
PMOVES.AI-Edition-Hardenedfrom
fix/api-key-validation

Conversation

@POWERFULMOVES

Copy link
Copy Markdown
Owner

Summary

Add pre-flight validation for LLM provider API keys to catch configuration issues before services start.

Changes

  • Add check for core LLM providers (OpenAI, Anthropic, Groq, Gemini, Ollama)
  • Warn if no LLM providers are configured
  • Display status of optional API keys (ElevenLabs, Voyage, Cohere, Cloudflare)
  • Detect empty/placeholder API key values (common mistake)

Example Output

Provider API Keys:
  Core LLM Providers (at least one recommended):
    ✓ OpenAI              configured
    • Anthropic           missing
    • Groq                missing
    • Google Gemini       missing
    • Ollama (local)      (will use http://localhost:11434)

  Optional API Keys:
    • ElevenLabs TTS                      not set (optional)
    • Voyage AI Embeddings                not set (optional)
    ...

  Checking for empty values:
    ✓ All API keys have values

Test Plan

  • Run make env-check with no API keys set
  • Run make env-check with one provider configured
  • Verify warning appears for empty/placeholder values

Resolves CROSS_PLATFORM_TASKS.md Issue K3 (Priority 2).

🤖 Generated with Claude Code

Add pre-flight validation for LLM provider API keys to catch
configuration issues before docker compose attempts to start services.

Changes:
- Add check for core LLM providers (OpenAI, Anthropic, Groq, Gemini, Ollama)
- Warn if no LLM providers are configured
- Display status of optional API keys (ElevenLabs, Voyage, Cohere, Cloudflare)
- Detect empty/placeholder API key values

Resolves CROSS_PLATFORM_TASKS.md - Issue K3 (Priority 2).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Feb 7, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/api-key-validation

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@POWERFULMOVES

Copy link
Copy Markdown
Owner Author

Review: Approved ✅

This PR adds useful API key validation to env_check.sh.

Changes Incorporated

This feature has been incorporated into the PMOVES.AI-Edition-Hardened branch (commit 87d4293e).

Minor Suggestion for Follow-up

There's a load_env function defined in the new code that duplicates an existing function in the same file. Consider refactoring to reuse the existing function in a future cleanup PR.

This doesn't block approval - the feature is valuable as-is.

POWERFULMOVES pushed a commit that referenced this pull request Feb 7, 2026
This commit incorporates the remaining changes from open PRs that were
not included in the initial port consistency fix commit:

**From PR #590 (WSL2 --project-directory)**
- Add --project-directory to apply_migrations_docker.sh
- Add --project-directory to smoke-tests.sh
- Add --project-directory to validate-phase1-hardening.sh
- Remove unsafe 'cd' pattern, use explicit paths instead

**From PR #591 (API Key Validation)**
- Add provider API key validation to env_check.sh
- Checks for OpenAI, Anthropic, Groq, Gemini, Ollama
- Warns about empty/placeholder API keys
- Provides helpful configuration tips

**From PR #587 (Security Update)**
- Update python-multipart to 0.0.22 (CVE-2026-24486 fix)
- Applied to agentgym-rl-coordinator and Enhanced Media Stack plans
- NOTE: Transformers constraint kept at <4.50.0 for FlagEmbedding

All superseded PRs can now be closed.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@POWERFULMOVES
POWERFULMOVES merged commit 354b631 into PMOVES.AI-Edition-Hardened Feb 7, 2026
1 check passed
POWERFULMOVES pushed a commit that referenced this pull request Feb 7, 2026
This commit brings all production hardening changes from PMOVES.AI-Edition-Hardened
into main, including:

## Submodule Updates
- Comprehensive submodule configuration updates (PR #598)
- All submodules verified and aligned to PMOVES.AI-Edition-Hardened branches

## Production Fixes
- Port consistency fixes (TensorZero internal port 3000 vs external 3030)
- WSL2 Docker Desktop compatibility (--project-directory flag in Makefile)
- ClickHouse URL format with embedded credentials
- Network cleanup improvements

## CI/CD Enhancements
- Provider API key validation added to env_check.sh (PR #591)
- Automated port consistency checking script

## Documentation
- WSL2 bring-up guide (PR #595)
- Production readiness audit documentation
- Submodule branch alignment audit

## Security
- All P0 security checks passing
- CODEOWNERS and Dependabot configured across submodules

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@POWERFULMOVES
POWERFULMOVES deleted the fix/api-key-validation branch March 7, 2026 21:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant