fix: send Scheduler API Bearer auth from the task registrar
The Scheduler's task-management endpoints (GET/POST /tasks, PUT
/tasks/{name}) are guarded by verify_api_key, but execute() built a bare
httpx.Client with no Authorization header: the existence probe 401'd
(misread as 'task absent') and every POST/PUT registration failed, so
--execute was never runnable end-to-end against the real Scheduler.
--execute now requires SCHEDULER_API_KEY from the environment (never
stored) and sends Authorization: Bearer on all registrar HTTP calls.
Deploy notes updated alongside the LIBRARY_API_KEY requirement.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QbFZyDvYksazX6nYQYZ67L
This commit is contained in:
@@ -12,11 +12,19 @@ SCHEDULER_URL=http://<scheduler-host>:8090 \
|
||||
|
||||
# Actually register/update the tasks (deploy checklist step):
|
||||
SCHEDULER_URL=http://<scheduler-host>:8090 \
|
||||
SCHEDULER_API_KEY=<scheduler-api-key> \
|
||||
.venv/bin/python scripts/register_scheduler_tasks.py --execute
|
||||
```
|
||||
|
||||
Conventions:
|
||||
|
||||
- The Scheduler's task-management endpoints (`GET`/`POST /tasks`,
|
||||
`PUT /tasks/{name}`) require `Authorization: Bearer $SCHEDULER_API_KEY`.
|
||||
The registrar reads `SCHEDULER_API_KEY` from the environment for its
|
||||
own HTTP calls (`--execute` refuses to run without it); the key is
|
||||
never stored. This is separate from `LIBRARY_API_KEY` below, which the
|
||||
Scheduler container needs at task **execution** time.
|
||||
|
||||
- All tasks call the **production** library-desk container
|
||||
(`http://library-desk:8089`) with the explicit production tenant
|
||||
`user=jpmschweitzer` (there is no default tenant — Phase B).
|
||||
|
||||
Reference in New Issue
Block a user