mirror of
https://gitcode.com/JianFeeeee/ModelRouter.git
synced 2026-09-20 00:48:00 +00:00
docs: remind to rotate the admin key after first start (seed key lives in plaintext config.yaml)
This commit is contained in:
@ -118,6 +118,8 @@ sources:
|
||||
|
||||
- `gateway_keys` 配置只是**初始 admin 密钥种子**:首次启动迁移为运行时 admin
|
||||
key,之后不再参与鉴权管理。
|
||||
- **重要:首次启动后请在 WebUI「密钥」页更换管理员密钥**——初始密钥明文写在
|
||||
`config.yaml` 里,继续使用存在被盗风险;用新密钥登录后删除初始密钥。
|
||||
- WebUI **密钥页**可创建/删除密钥;每个密钥可指定 `admin`(管理全部)或
|
||||
`user`(仅看自己的 key)角色,并配置**模型范围**(模型 + 源 + token 配额 +
|
||||
重置周期)。
|
||||
|
||||
@ -142,6 +142,10 @@ under the `keys` field of the runtime file (encrypted at rest):
|
||||
|
||||
- The `gateway_keys` config is only an **initial admin key seed** — it is
|
||||
migrated into the runtime store on first start and no longer drives auth.
|
||||
- **Important: after first start, replace the admin key via the WebUI Keys
|
||||
page.** The seed key is written in plaintext in `config.yaml`, so keeping it
|
||||
active is a security risk; create a new admin key, log in with it, then
|
||||
delete the seed key.
|
||||
- The WebUI **Keys page** creates/deletes keys. Each key has a role (`admin`
|
||||
manages everything, `user` sees only its own key) and an optional **model
|
||||
scope** (model + source + token quota + reset period).
|
||||
|
||||
@ -6,6 +6,8 @@ listen: 127.0.0.1:8080
|
||||
# 网关自身鉴权密钥。现在为「多密钥」架构:此项仅作为初始 admin 密钥种子,
|
||||
# 首次启动写入运行时存储(runtime_file 的 keys 字段,加密存储)。之后请在
|
||||
# WebUI「密钥」页创建、删除密钥并配置其模型范围。留空 = 首启无 admin 密钥。
|
||||
# 注意:首次启动后应立即在 WebUI 更换管理员密钥,并删除本初始种子——它明文
|
||||
# 写在配置文件里,存在被窃取风险。
|
||||
gateway_keys:
|
||||
- sk-gw-local-0001
|
||||
|
||||
|
||||
Reference in New Issue
Block a user