Skip to content

Load local Gemini credentials in botenv - #29

Open
ma08 wants to merge 1 commit into
mainfrom
sourya4/zon-217-gemini-secret-bootstrap
Open

Load local Gemini credentials in botenv#29
ma08 wants to merge 1 commit into
mainfrom
sourya4/zon-217-gemini-secret-bootstrap

Conversation

@ma08

@ma08 ma08 commented Jul 25, 2026

Copy link
Copy Markdown
Owner

Summary

  • Add the ignored machine-local secrets/local/gemini.rc to .botenv's fixed, deterministic secret-source list.
  • Enable GEMINI_API_KEY for interactive shells, non-interactive jobs, SSH commands, and agent processes without placing the key in tracked configuration.

Validation

  • bash -n .botenv
  • sh -n .botenv
  • On research-cpu-01, a fresh shell loaded the local credential and a bounded Gemini gemini-3.6-flash request returned HTTP 200.

Security

  • secrets/local/ remains ignored; this PR contains no credential value.
  • The deployed Gemini key is service-account-bound and restricted to generativelanguage.googleapis.com.

Written by Codex via the developer's authenticated GitHub account.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant