Skip to content

Switch install-script API keys to single-instance bootstrap-key pattern

Placeholder ppxd requested to merge feat/bootstrap-key-get-or-create into main

Summary

Phase 3 of the bootstrap-key redesign. Re-filed after PR #336 was auto-closed when its base (PR #338, Phase 2) merged.

Closes the "DB accumulates one row per install-script call" issue. The 1.6.x mint-per-call pattern created a fresh `user_account_api_key` row on every Add-Tentacle click. New pattern: canonical stable description + `FindApiKeyByDescriptionAsync` first, mint only on first install or after rotation.

`TentacleBootstrapKeyDescription` + `KubernetesAgentBootstrapKeyDescription` are public consts consumed by Phase 4's rotation endpoint.

Adds `IAccountService.FindApiKeyByDescriptionAsync` returning the new internal `ApiKeyWithSecret` record (raw key value -- trusted-Core-only, never exposed via controllers).

Test plan

  • Unit: 5236/5236 pass
  • 6 new tests: Find/SharedKey/NoSharedKey pins on both Tentacle + K8s paths
  • CI on the predecessor PR (#336) was fully green (9/9) before re-target

🤖 Generated with Claude Code

Merge request reports

Loading