docs: remind to rotate the admin key after first start (seed key lives in plaintext config.yaml)

This commit is contained in:
root
2026-08-10 11:53:14 +08:00
parent f46b02089c
commit a5c370018c
3 changed files with 8 additions and 0 deletions

View File

@ -142,6 +142,10 @@ under the `keys` field of the runtime file (encrypted at rest):
- The `gateway_keys` config is only an **initial admin key seed** — it is
migrated into the runtime store on first start and no longer drives auth.
- **Important: after first start, replace the admin key via the WebUI Keys
page.** The seed key is written in plaintext in `config.yaml`, so keeping it
active is a security risk; create a new admin key, log in with it, then
delete the seed key.
- The WebUI **Keys page** creates/deletes keys. Each key has a role (`admin`
manages everything, `user` sees only its own key) and an optional **model
scope** (model + source + token quota + reset period).