Skip to content

v1.19.1

Latest

Choose a tag to compare

@bnsoni bnsoni released this 14 Aug 14:42
dbb4f23

[1.19.1] — 2026-08-14

Patch release. Recommended for anyone who has set or rotated an LLM API key with this CLI — see Upgrading.

Fixed

  • The LLM API key did not reach the platform. The credential row keeps the same secret in two columns — a plaintext one and an encrypted one — and current platform versions read the encrypted column as the source of truth, without falling back to plaintext. iblai infra llm set-key wrote only the plaintext column, so on a fresh environment the key stayed inert, and on a rotation the previous key remained in force — while the command reported success either way. The platform's own backfill does not repair a rotation: it fills the encrypted column only when that column is empty. Both columns are now written together with the same {"key": "..."} payload, and the columns are looked up on the model first so older deployments that never had the encrypted one still work.
  • Setting a key now clears is_preferred on the other providers. The platform takes the first preferred credential with no tie-break, so two preferred rows meant an arbitrary one won and a newly set key could be ignored.
  • An API key can no longer carry shell or Python syntax. The key is interpolated into a command that wraps a Python program, where a quote ends the Python literal, a double quote ends the shell string, and $(...) is substituted by the shell before the command runs. Keys are now checked against an allowlist of the characters providers actually issue — on the model, so the wizard, the flag and the .env path are covered at once — and asserted again in the role so the check does not depend on its caller. This matters most in CI, where the key comes from a secret store rather than from the operator running the command.
  • The key is no longer echoed if the task fails. It is interpolated into the command, which Ansible prints on failure, and into any CI log capturing that output.

Added

  • iblai infra llm set-key --provider openai|anthropic. The credential is named for its provider and the platform matches that name exactly, so the value is validated and lowercased rather than passed through. Interactive runs pick from a list; non-interactive runs default to openai, unchanged.

Upgrading

No migration, and existing environments are not repaired retroactively. Any environment whose LLM key was set or rotated through the CLI is still running on whatever is in its encrypted column — re-run set-key on this version to correct it:

uv tool upgrade iblai-infra     # or: uv tool install --force git+https://github.com/iblai/infra-cli
iblai --version                 # iblai v1.19.1
iblai infra llm set-key <name>

Test count: 929 passing.

Full changelog: v1.19.0...v1.19.1