Skip to content

Hotline Computer 0.7.0

Choose a tag to compare

@1broseidon 1broseidon released this 20 Sep 19:57
· 43 commits to main since this release

Hotline Computer 0.7.0 takes the person's secrets from the desk and keeps every value out of what it answers.

  • PUT /secrets, bearer in the Authorization header, hands the computer the whole set of secrets the desk was told to grant: a JSON object of name to value, replaced whole each time. The set lives in the service's memory and nowhere else. Every job the agent starts through shell or files run finds each entry as an environment variable under the name the person gave it — above the workspace's saved environment, under the agent's own env. A preparation job is left out, because what it captures is written into the workspace.
  • Nothing answers a value. The route is PUT-only, state info lists the names alone, and every text a tool returns has each value replaced with [redacted NAME] on its way out, in the spelling JSON gives it too. That keeps a value out of the agent's context when a command prints it; it does not stop a command written to get one out, and the README says so. One entry the computer would not put in a job's environment refuses the whole set with a 400 that names it.
  • A job no longer inherits HOTLINE_COMPUTER_TOKEN. The bearer is the service's door key; it should not lie in every command's environment.
  • /files also takes the bearer as an Authorization header, so a caller that is not a browser — the desk, bringing over cookies — keeps the token out of the URL. The token query stays for the viewer page, which cannot set a header.
  • The skill tells the agent how to use a secret it was given and that it will never see one: state info for the names, $NAME in a command, ask the person for one it was not given.

Hotline desk 0.15.0 is the first that stores secrets and grants them; a desk on 0.14.x drives this computer as before and grants nothing. Existing computers retain their running version until updated from the teammate's pane; state info and state guide identify the attached computer.

Validation: native ARM64/x86_64 release gates passed all 22 scenarios per architecture, the image contract (now including the secrets pass), restart plus recreate recovery on the same home and store volumes, image-identity checks, and cold pulls.

Cold registry pulls: 15.25 s ARM64 / 15.57 s x86_64. Downloaded-image start-to-health: 0.953 s / 0.468 s. Compressed layers: 424,842,126 / 424,696,238 bytes. The combined image digest is sha256:7d2fe99752ec31437c62db9a7376b847e605e126be50b5cbd2fd8b6fad71827f.

Use ghcr.io/1broseidon/hotline-computer:0.7.0.