Skip to content

feat: agent-secrets - #374

Merged
yxtay merged 6 commits into
mainfrom
feat/agent-secrets
Jul 29, 2026
Merged

feat: agent-secrets#374
yxtay merged 6 commits into
mainfrom
feat/agent-secrets

Conversation

@yxtay

@yxtay yxtay commented Jul 29, 2026

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • Configuration
    • Expanded integration setup options with additional service and API key settings.
    • Added configuration examples for LiteLLM database connectivity and master key authentication.
    • Updated deployment configuration to require an explicitly provided LiteLLM database connection.
    • Removed the previous default database connection fallback, helping prevent unintended database usage.

@coderabbitai

coderabbitai Bot commented Jul 29, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@yxtay, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 41 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 777c2c62-1e91-4e3d-825a-dae1754505bf

📥 Commits

Reviewing files that changed from the base of the PR and between bc9ce87 and 2e06375.

📒 Files selected for processing (1)
  • agent/.env.example
📝 Walkthrough

Walkthrough

LiteLLM configuration examples now include additional integration keys, a database URL, and a master key. The compose service uses the explicitly provided LITELLM_DATABASE_URL without a fallback default.

Changes

LiteLLM configuration

Layer / File(s) Summary
Environment variable examples
agent/.env.example
Adds integration API-key placeholders, removes GOOGLE_API_KEY, and adds LITELLM_DATABASE_URL and LITELLM_MASTER_KEY.
Required database wiring
agent/compose.yaml
Configures the litellm service to require LITELLM_DATABASE_URL instead of using a default PostgreSQL URL.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Possibly related PRs

Poem

A bunny found keys in a row,
With LiteLLM’s database aglow.
No fallback to hide,
The URL must reside,
Hop-hop—the configs now flow!

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Title check ❓ Inconclusive The title is related to the change, but "agent-secrets" is too vague to quickly convey the main update. Rename it to mention the specific secret/config updates, e.g. "feat: add agent service secrets and LiteLLM env config".
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/agent-secrets

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 29, 2026

Copy link
Copy Markdown

MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ BASH shfmt 11 0 0 0 0.02s
✅ JSON prettier 1 0 0 0 0.33s
✅ MARKDOWN markdownlint 5 0 0 0 0.57s
✅ MARKDOWN markdown-table-formatter 5 0 0 0 0.15s
✅ TERRAFORM terraform-fmt 7 0 0 0 0.31s
✅ YAML prettier 49 0 0 0 0.96s

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters BASH_SHFMT,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,TERRAFORM_TERRAFORM_FMT,YAML_PRETTIER

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@agent/.env.example`:
- Line 3: Update the optional API key placeholders in the environment example,
including BRAVE_SEARCH_API_KEY and NOUS_API_KEY, to use explicit empty
assignments with “=” like the other entries; preserve the existing key names and
ordering.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5829e5b2-0bbf-4310-98cb-37169d85af96

📥 Commits

Reviewing files that changed from the base of the PR and between 54bc164 and bc9ce87.

📒 Files selected for processing (2)
  • agent/.env.example
  • agent/compose.yaml

Comment thread agent/.env.example Outdated
@github-actions

github-actions Bot commented Jul 29, 2026

Copy link
Copy Markdown

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 4 0 0 0.35s
✅ ACTION zizmor 4 0 0 0 0.4s
✅ BASH bash-exec 11 0 0 0.02s
✅ BASH shellcheck 11 0 0 0.23s
✅ BASH shfmt 11 0 0 0 0.01s
⚠️ COPYPASTE jscpd yes 1 no 0.13s
✅ EDITORCONFIG editorconfig-checker 107 0 0 0.14s
✅ JSON prettier 1 0 0 0 0.35s
✅ JSON v8r 1 0 0 1.65s
✅ MARKDOWN markdownlint 5 0 0 0 0.83s
✅ MARKDOWN markdown-table-formatter 5 0 0 0 0.16s
✅ REPOSITORY betterleaks yes no no 0.98s
✅ REPOSITORY checkov yes no no 26.67s
✅ REPOSITORY gitleaks yes no no 0.74s
✅ REPOSITORY git_diff yes no no 0.01s
✅ REPOSITORY grype yes no no 65.38s
✅ REPOSITORY osv-scanner yes no no 0.2s
✅ REPOSITORY secretlint yes no no 1.27s
✅ REPOSITORY syft yes no no 1.99s
✅ REPOSITORY trivy yes no no 14.56s
✅ REPOSITORY trivy-sbom yes no no 0.09s
✅ REPOSITORY trufflehog yes no no 6.12s
⚠️ SPELL lychee 56 41 0 2.26s
✅ YAML prettier 49 0 0 0 1.12s
✅ YAML v8r 49 0 0 16.54s
✅ YAML yamllint 49 0 0 1.14s

Detailed Issues

⚠️ COPYPASTE / jscpd - 1 error
Using config from /action/lib/.automation/.jscpd.json
Clone found (bash)
 - bin/oci-rm-stack-create.sh [32:1 - 40:5] (9 lines, 51 tokens)
   bin/oci-rm-stack-update.sh [12:1 - 20:5]
┌────────┬────────────────┬─────────────┬──────────────┬──────────────┬──────────────────┬───────────────────┐
│ Format │ Files analyzed │ Total lines │ Total tokens │ Clones found │ Duplicated lines │ Duplicated tokens │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ bash   │ 7              │ 214         │ 1120         │ 1            │ 8 (3.74%)        │ 51 (4.55%)        │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ hcl    │ 4              │ 382         │ 1407         │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ txt    │ 1              │ 29          │ 379          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ Total: │ 12             │ 625         │ 2906         │ 1            │ 8 (1.28%)        │ 51 (1.75%)        │
└────────┴────────────────┴─────────────┴──────────────┴──────────────┴──────────────────┴───────────────────┘
Found 1 clones.
HTML report saved to megalinter-reports/copy-paste/jscpd-report.html
ERROR: jscpd found too many duplicates (1.3%) over threshold (0.0%)
time: 27.213ms
⚠️ SPELL / lychee - 41 errors
📝 Summary
---------------------
🔍 Total...........68
🔗 Unique..........58
✅ Successful......20
⏳ Timeouts.........0
🔀 Redirected.......0
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors..........41
⛔ Unsupported.....41

Errors in agent/compose.yaml
[ERROR] http://localhost:2375/_ping (at 89:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:4000/health/liveliness (at 129:70) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9119/api/status (at 41:33) | Connection refused - server may be down or port blocked
[ERROR] https://hermes/ (at 12:67) | Connection failed. Check network connectivity and firewall settings

Errors in agent/litellm/config.yaml
[ERROR] http://headroom:8787/ (at 82:19) | Connection failed. Check network connectivity and firewall settings
[404] https://inference-api.nousresearch.com/v1 (at 62:17) | Rejected status code: 404 Not Found
[404] https://opencode.ai/zen/go/v1 (at 74:17) | Rejected status code: 404 Not Found
[404] https://opencode.ai/zen/v1 (at 68:17) | Rejected status code: 404 Not Found

Errors in arcane/compose.yaml
[ERROR] http://localhost:3552/ (at 6:27) | Connection refused - server may be down or port blocked

Errors in homeassistant/compose.yaml
[ERROR] http://localhost:10000/health (at 146:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:6052/version (at 105:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8095/ (at 66:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8123/ (at 27:33) | Connection refused - server may be down or port blocked

Errors in immich/compose.yaml
[ERROR] http://localhost:8080/ (at 160:32) | Connection refused - server may be down or port blocked

Errors in infra/compose.yaml
[ERROR] http://localhost:2375/_ping (at 60:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9002/healthz (at 95:36) | Connection refused - server may be down or port blocked

Errors in monitoring/compose.yaml
[ERROR] http://localhost:8090/ (at 73:44) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8090/ (at 94:27) | Connection refused - server may be down or port blocked

Errors in pangolin/compose.yaml
[ERROR] http://gerbil:3004/ (at 63:23) | Connection failed. Check network connectivity and firewall settings
[ERROR] http://localhost/ping (at 121:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:3001/api/v1/ (at 51:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:3004/healthz (at 87:32) | Connection refused - server may be down or port blocked
[ERROR] http://pangolin:3001/api/v1/ (at 65:24) | Connection failed. Check network connectivity and firewall settings

Errors in pangolin/traefik/dynamic/config.yml
[ERROR] http://pangolin:3000/ (at 80:18) | Connection failed. Check network connectivity and firewall settings
[ERROR] http://pangolin:3002/ (at 85:18) | Connection failed. Check network connectivity and firewall settings

Errors in pangolin/traefik/traefik.template.yml
[ERROR] http://pangolin:3001/api/v1/traefik-config (at 7:15) | Connection failed. Check network connectivity and firewall settings

Errors in proxy/compose.yaml
[ERROR] http://localhost/healthz (at 36:32) | Connection refused - server may be down or port blocked
[ERROR] https://tinyauth/ (at 50:24) | Connection failed. Check network connectivity and firewall settings

Errors in security/compose.yaml
[ERROR] http://localhost:8080/ (at 52:16) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8080/health (at 34:32) | Connection refused - server may be down or port blocked

Errors in torrent/compose.yaml
[ERROR] http://localhost:6868/ (at 220:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:7878/ping (at 140:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8191/health (at 16:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8989/ping (at 182:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9696/ping (at 45:33) | Connection refused - server may be down or port blocked
[ERROR] https://profilarr/ (at 205:15) | Connection failed. Check network connectivity and firewall settings

Errors in usenet/compose.yaml
[ERROR] http://127.0.0.1:7000/ (at 83:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:1337/ (at 288:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:3000/health (at 26:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:7000/health (at 134:32) | Connection refused - server may be down or port blocked
[ERROR] https://aiostreams/ (at 232:18) | Connection failed. Check network connectivity and firewall settings

Hint: You can configure accepted/rejected response codes with `-a` or `--accept`

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,BASH_EXEC,BASH_SHELLCHECK,BASH_SHFMT,COPYPASTE_JSCPD,EDITORCONFIG_EDITORCONFIG_CHECKER,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Jul 29, 2026

Copy link
Copy Markdown

MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ BASH bash-exec 11 0 0 0.05s
✅ BASH shellcheck 11 0 0 0.28s
✅ REPOSITORY betterleaks yes no no 1.79s
✅ REPOSITORY checkov yes no no 28.13s
✅ REPOSITORY dustilock yes no no 0.04s
✅ REPOSITORY gitleaks yes no no 0.85s
✅ REPOSITORY grype yes no no 67.19s
✅ REPOSITORY kingfisher yes no no 15.17s
✅ REPOSITORY osv-scanner yes no no 0.42s
✅ REPOSITORY secretlint yes no no 1.74s
✅ REPOSITORY syft yes no no 2.38s
✅ REPOSITORY trivy yes no no 11.24s
✅ REPOSITORY trivy-sbom yes no no 0.11s
✅ REPOSITORY trufflehog yes no no 3.6s
✅ TERRAFORM tflint yes no no 8.21s

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters BASH_EXEC,BASH_SHELLCHECK,REPOSITORY_CHECKOV,REPOSITORY_DUSTILOCK,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,REPOSITORY_KINGFISHER,TERRAFORM_TFLINT

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

@yxtay
yxtay merged commit 53dfc01 into main Jul 29, 2026
30 checks passed
@yxtay
yxtay deleted the feat/agent-secrets branch July 29, 2026 02:17
This was referenced Jul 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant