Relationships
#2866 Docs: SWAMP_API_KEY_FILE and serve --club-api-key-file
Opened by stack72 · 9/30/2026
swamp-club#2790 adds two ways to supply the collective API key from a file instead of the SWAMP_API_KEY env var:
- SWAMP_API_KEY_FILE: an env var holding a path to a file that contains the key. It works for every command that uses SWAMP_API_KEY today (auth whoami, extension push/pull, issue commands, telemetry, serve).
- --club-api-key-file
: a flag on swamp serve and swamp serve check-config (forwarded by swamp serve daemon enable). The key serve uses for OAuth client registration, admin/allowed-user name lookup, instance registration and the club heartbeat is read from this file, and the same key is used for extension trust, pulls and telemetry in that process.
Precedence: --club-api-key-file, then SWAMP_API_KEY_FILE, then SWAMP_API_KEY. Setting both SWAMP_API_KEY and SWAMP_API_KEY_FILE is an error. One trailing newline in the file is stripped, and a missing, unreadable or empty file is an error naming the source. Serve reads the key once per boot, so a rotated file needs a restart.
Pages to update in content/manual/reference:
- api-key-authentication.md: add SWAMP_API_KEY_FILE next to SWAMP_API_KEY, with the precedence and the mutual-exclusivity rule.
- swamp-serve.md: document --club-api-key-file for headless OAuth registration, with a container/Kubernetes secret-mount example, and note that daemon enable stores only the path.
Closed
No activity in this phase yet.
stack72 commented 10/2/2026, 1:46:23 AM
Documented in https://github.com/swamp-club/swamp-club/pull/1281. api-key-authentication.md already covered SWAMP_API_KEY_FILE, the precedence and the mutual-exclusion error. swamp-serve.md is only an index page, so the flag went into reference/swamp-serve/serve-flags.md (a --club-api-key-file row and a SWAMP_API_KEY_FILE env row) and reference/swamp-serve/daemon.md, which notes that daemon enable stores only the path. how-to/swamp-serve/deploy-headless-oauth.md gains a Kubernetes secret-volume example, the restart-on-rotation note, and the missing-file error. One correction to the issue text: the key file is trimmed of all surrounding whitespace, not just one trailing newline (api_key_source.ts).
Sign in to post a ripple.