Skip to main content
← Back to list
01Issue
FeatureClosedSwamp ClubPublic
AssigneesNone

Relationships

#2866 Docs: SWAMP_API_KEY_FILE and serve --club-api-key-file

Opened by stack72 · 9/30/2026

swamp-club#2790 adds two ways to supply the collective API key from a file instead of the SWAMP_API_KEY env var:

  • SWAMP_API_KEY_FILE: an env var holding a path to a file that contains the key. It works for every command that uses SWAMP_API_KEY today (auth whoami, extension push/pull, issue commands, telemetry, serve).
  • --club-api-key-file : a flag on swamp serve and swamp serve check-config (forwarded by swamp serve daemon enable). The key serve uses for OAuth client registration, admin/allowed-user name lookup, instance registration and the club heartbeat is read from this file, and the same key is used for extension trust, pulls and telemetry in that process.

Precedence: --club-api-key-file, then SWAMP_API_KEY_FILE, then SWAMP_API_KEY. Setting both SWAMP_API_KEY and SWAMP_API_KEY_FILE is an error. One trailing newline in the file is stripped, and a missing, unreadable or empty file is an error naming the source. Serve reads the key once per boot, so a rotated file needs a restart.

Pages to update in content/manual/reference:

  • api-key-authentication.md: add SWAMP_API_KEY_FILE next to SWAMP_API_KEY, with the precedence and the mutual-exclusivity rule.
  • swamp-serve.md: document --club-api-key-file for headless OAuth registration, with a container/Kubernetes secret-mount example, and note that daemon enable stores only the path.
02Bog Flow
✓OPEN○TRIAGED○IN PROGRESS◉CLOSED

Closed

10/2/2026, 1:46:23 AM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

stack72 commented 10/2/2026, 1:46:23 AM

Documented in https://github.com/swamp-club/swamp-club/pull/1281. api-key-authentication.md already covered SWAMP_API_KEY_FILE, the precedence and the mutual-exclusion error. swamp-serve.md is only an index page, so the flag went into reference/swamp-serve/serve-flags.md (a --club-api-key-file row and a SWAMP_API_KEY_FILE env row) and reference/swamp-serve/daemon.md, which notes that daemon enable stores only the path. how-to/swamp-serve/deploy-headless-oauth.md gains a Kubernetes secret-volume example, the restart-on-rotation note, and the missing-file error. One correction to the issue text: the key file is trimmed of all surrounding whitespace, not just one trailing newline (api_key_source.ts).

Sign in to post a ripple.