# Service credential compartments These drop-ins replace a shared all-secrets `EnvironmentFile` with one service-specific file. They are templates, not an activation script. The credential files are generated from an existing private assignment file without evaluating shell expressions or printing values: ```sh pnpm split:service-credentials -- \ --source /path/to/private.env \ --output-dir "$HOME/.config/thoughtstream/credentials" \ --consumer-providers letta ``` Use `--consumer-providers tinker,openai` for the production Pi/Tinker Telegram agent plus the fixed `openai-json-default` conceptualizer. `openai` selects only `OPENAI_API_KEY`; `openai-compatible` selects the separately configured `THOUGHTSTREAM_MODEL_*` profile. Do not retain `letta` after all enabled Letta runner declarations have been removed. The splitter refuses to remove existing assignments silently. Intentional revocation requires one `--allow-remove VARIABLE_NAME` per removed variable; malformed, duplicate, extra, or stale allowances fail closed. Do not reuse removal allowances on later runs. The splitter writes an owner-only directory and eight mode-0600 files. It refuses Git worktrees and configured public-content roots. Its receipt contains paths and variable names only. `fastmail-jmap.env` contains only `FASTMAIL_API_KEY`. `x-webhook.env` contains only the consumer secret needed for CRC and POST signatures. `x-management.env` contains the app bearer token and optional test base URL; load it only for explicit `x-webhook-*` and `x-subscriptions-*` management commands, never the receiver service. Use `letta` for Cloud-backed declarations that need `LETTA_API_KEY`. Use `letta-local` for API-backed local Agent SDK declarations that use existing agent identity and ChatGPT OAuth without placing a Cloud API key in the consumer compartment. Combine either with `tinker` or `openai-compatible` when the same consumer process owns those declarations. The splitter treats every `THOUGHTSTREAM_LETTA_*` assignment as consumer-only state. This includes the separate Bluesky, X, and social listener agent ids and their explicit activation gates. Adding those values to the source file does not enable their tracked batch declarations or provision the Cloud agents; activation still requires a private-manifest change and a coordinated consumer restart after source-local canaries pass. Install each template as `credentials.conf` beneath the corresponding user-unit drop-in directory, then run `systemctl --user daemon-reload`. Restart only the affected units and verify their effective `EnvironmentFiles` and loaded code paths. Do not inspect `Environment` or print file contents as verification. The Jetstream compartment intentionally carries no model or Telegram credential. It is activatable only with a producer-only Jetstream command. This slice is based on `d7abc76`, whose Jetstream command also starts consumers; producer-only support must exist in the target branch before installing this drop-in or enabling Jetstream.