Skip to content

[awf] api-proxy: accept engine-agnostic BYO-endpoint API key (AGENT_API_KEY alias) #9543

Description

@lpcox

Problem
Reusable workflow_call workflows must declare engine-specific secret names (CODEX_API_KEY, ANTHROPIC_API_KEY, COPILOT_PROVIDER_API_KEY). Switching engine.id renames the secret, breaking every caller across repos.

Context
Original: github/gh-aw#54488 (gh-aw v0.86.2). Requests a generic AGENT_API_KEY alias routed to the engine's native env var, with native names still accepted.

Root Cause
Mostly a gh-aw compiler/validation concern, but AWF's api-proxy (containers/api-proxy/) and CLI key handling (src/docker-manager.ts, src/services/) read provider-specific env vars (OPENAI_API_KEY, ANTHROPIC_API_KEY, COPILOT_PROVIDER_API_KEY) with no provider-neutral entry point.

Proposed Solution

  1. Compiler (gh-aw) maps AGENT_API_KEY to the native env var for the selected engine before invoking awf.
  2. In AWF, optionally accept a neutral AWF_AGENT_API_KEY and resolve it to the active provider's adapter key when that provider's native var is unset, with native vars taking precedence.
  3. Ensure the key is excluded from the agent container env when --enable-api-proxy is active, and add tests plus docs in docs/environment.md.

Generated by Firewall Issue Dispatcher · copilot · auto · 23.2 AIC · ⊞ 9.3K · ◷

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions