Problem
Reusable workflow_call workflows must declare engine-specific secret names (CODEX_API_KEY, ANTHROPIC_API_KEY, COPILOT_PROVIDER_API_KEY). Switching engine.id renames the secret, breaking every caller across repos.
Context
Original: github/gh-aw#54488 (gh-aw v0.86.2). Requests a generic AGENT_API_KEY alias routed to the engine's native env var, with native names still accepted.
Root Cause
Mostly a gh-aw compiler/validation concern, but AWF's api-proxy (containers/api-proxy/) and CLI key handling (src/docker-manager.ts, src/services/) read provider-specific env vars (OPENAI_API_KEY, ANTHROPIC_API_KEY, COPILOT_PROVIDER_API_KEY) with no provider-neutral entry point.
Proposed Solution
- Compiler (gh-aw) maps
AGENT_API_KEY to the native env var for the selected engine before invoking awf.
- In AWF, optionally accept a neutral
AWF_AGENT_API_KEY and resolve it to the active provider's adapter key when that provider's native var is unset, with native vars taking precedence.
- Ensure the key is excluded from the agent container env when
--enable-api-proxy is active, and add tests plus docs in docs/environment.md.
Generated by Firewall Issue Dispatcher · copilot · auto · 23.2 AIC · ⊞ 9.3K · ◷
Problem
Reusable
workflow_callworkflows must declare engine-specific secret names (CODEX_API_KEY,ANTHROPIC_API_KEY,COPILOT_PROVIDER_API_KEY). Switchingengine.idrenames the secret, breaking every caller across repos.Context
Original: github/gh-aw#54488 (gh-aw v0.86.2). Requests a generic
AGENT_API_KEYalias routed to the engine's native env var, with native names still accepted.Root Cause
Mostly a gh-aw compiler/validation concern, but AWF's api-proxy (
containers/api-proxy/) and CLI key handling (src/docker-manager.ts,src/services/) read provider-specific env vars (OPENAI_API_KEY,ANTHROPIC_API_KEY,COPILOT_PROVIDER_API_KEY) with no provider-neutral entry point.Proposed Solution
AGENT_API_KEYto the native env var for the selected engine before invokingawf.AWF_AGENT_API_KEYand resolve it to the active provider's adapter key when that provider's native var is unset, with native vars taking precedence.--enable-api-proxyis active, and add tests plus docs indocs/environment.md.