Files
wehub-resource-sync 426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:43:05 +08:00

5.3 KiB

Team credential pooling — Phase 1 (org API-key pool)

Issue: elizaOS/eliza#11332. Design doc: "Team Credential-Pooling for Eliza Cloud" (Phase 1). This file records the WHY behind the implementation choices in src/lib/services/team-credential-pool/ and the two follow-up seams.

What it is

Any org member contributes provider API keys (Anthropic / OpenAI / Cerebras / DeepSeek / Z.ai / Moonshot console keys) to the org's pool. Dedicated-agent provisioning rotates across them with the exact selection/health behavior of the self-host AccountPool.

Architecture (reuse map)

Piece Source
Rotation/health brain AccountPool from @elizaos/app-core/account-pool, unchanged — cloud supplies DrizzleAccountPoolDeps
Ciphertext store existing secrets vault (AES-256-GCM envelope, audit log). pooled_credentials.secret_idsecrets.id
Metadata columns mirror LinkedAccountConfig / LinkedAccountHealthDetail / LinkedAccountUsage from @elizaos/contracts 1:1
Pre-pool validation probePooledApiKey, patterned on packages/agent/src/auth/direct-api-probe.ts (#11033) — kept local so the Worker bundle never pulls @elizaos/agent
Per-org isolation TeamPoolRegistry Map<orgId, AccountPool> with LRU eviction. The self-host globalThis bridges are never used (single-tenant plumbing)
IDOR guard assertOrgMembership on the :credentialId routes
Usage attribution pooled_credential_usage daily rollup (org, credential, user, day, calls) — replaces the self-host JSONL log

readAccounts in AccountPoolDeps is synchronous by contract, so DrizzleAccountPoolDeps serves a snapshot refreshed from the DB (15s TTL on acquire). writeAccount is a row-level UPDATE of pool-metadata columns only — never a blob rewrite — which removes the self-host read-modify-write hazard.

Injection points

  1. Dedicated containers (implemented). createRuntimeAgent (eliza-sandbox.ts) merges pooled keys into the in-memory bootstrap env right after decryptAgentEnvVars, only for providers the agent has no key of its own. The payload flows through buildRuntimeBootstrapAgent into character settings.secrets. Pooled keys are never persisted into environment_vars. Strict fallback: any pool failure yields the env unchanged (exactly today's behavior).
  2. Worker shared-runtime inference (documented seam, NOT implemented). getProviderKeys (lib/providers/provider-env.ts) is synchronous and has no organization in scope; consulting the org pool there requires an async org-context refactor of every call site plus a node-side broker for decryption. Rather than half-build it, the follow-up contract is: before the platform-env fallback, call getTeamPoolRegistry().selectCredential({ organizationId, providerId }) with a strict fallback to platform env on any pool miss, and record provider outcomes back through the org pool — 401 → pool.markNeedsReauth, 429 → pool.markRateLimited — exactly as credential-store.ts does for self-host chat. (That writeback surface ships with the wiring; Phase 1 deliberately adds no caller-less API.) Until then, key revocation is detected by the keep-alive sweep, which re-probes healthy credentials on a 6h cadence and flags 401/403s.

Who can see what

  • Plaintext is never returned — not even in the POST response (the contributor just typed the key; echoing it back would only re-expose it in transit, on screen, and in client state). The contribution response is the same masked summary as every read.
  • Every read (GET) is masked: label, provider, last4, health, usage, contributor, per-day calls. Owner/admin can disable/re-prioritize/delete but never reveal. Contributors can delete their own key.
  • Decryption happens only server-side at use time (SecretsService), and every decrypt lands in secret_audit_log.

Billing — zero-rated (deliberate)

Pooled-key usage does not decrement org credit_balance and carries no platform fee: the org already pays the provider directly on its own console account, and cloud infra cost for the pool is negligible (a DB read per provision).

Future monetization (documented, NOT implemented)

If pooled-key usage should later contribute to cloud revenue, the metering point is already in place — TeamPoolRegistry.recordUse fires once per selection with (org, credential, user). Options, in increasing coupling:

  1. Platform fee per pooled call — emit a credit_transactions debit from recordUse at a flat per-call or per-day rate.
  2. Metered credits — extend recordUse with token counts from the inference layer and charge a discounted ai_billing_records rate (BYO-key tier) instead of the full markup.
  3. Seat-gated feature — leave usage free but gate pool size (N keys per org) behind the subscription plan, enforced at contributePooledCredential.

All three are additive at the two named call sites; none require schema changes (usage rollup already attributes per member per day).

Phase 2 (not in this change)

Subscription-seat pooling (Claude Max / Codex) stays rejected at the API layer (isSubscriptionProviderId). The Phase 2 design (flag + org allowlist + tokens confined to first-party CLIs in single-tenant containers via CredentialTunnelService) is in the design doc; nothing here builds it.