Service credential compartments #
These drop-ins replace a shared all-secrets EnvironmentFile with one service-specific file. They are templates, not an activation script.
The credential files are generated from an existing private assignment file without evaluating shell expressions or printing values:
pnpm split:service-credentials -- \
--source /path/to/private.env \
--output-dir "$HOME/.config/thoughtstream/credentials" \
--consumer-providers letta
Use --consumer-providers tinker,openai for the production Pi/Tinker Telegram agent plus the fixed openai-json-default conceptualizer. openai selects only OPENAI_API_KEY; openai-compatible selects the separately configured THOUGHTSTREAM_MODEL_* profile. Do not retain letta after all enabled Letta runner declarations have been removed.
The splitter refuses to remove existing assignments silently. Intentional revocation requires one --allow-remove VARIABLE_NAME per removed variable; malformed, duplicate, extra, or stale allowances fail closed. Do not reuse removal allowances on later runs.
The splitter writes an owner-only directory and eight mode-0600 files. It refuses Git worktrees and configured public-content roots. Its receipt contains paths and variable names only. fastmail-jmap.env contains only FASTMAIL_API_KEY. x-webhook.env contains only the consumer secret needed for CRC and POST signatures. x-management.env contains the app bearer token and optional test base URL; load it only for explicit x-webhook-* and x-subscriptions-* management commands, never the receiver service.
Use letta for Cloud-backed declarations that need LETTA_API_KEY. Use letta-local for API-backed local Agent SDK declarations that use existing agent identity and ChatGPT OAuth without placing a Cloud API key in the consumer compartment. Combine either with tinker or openai-compatible when the same consumer process owns those declarations.
The splitter treats every THOUGHTSTREAM_LETTA_* assignment as consumer-only state. This includes the separate Bluesky, X, and social listener agent ids and their explicit activation gates. Adding those values to the source file does not enable their tracked batch declarations or provision the Cloud agents; activation still requires a private-manifest change and a coordinated consumer restart after source-local canaries pass.
Install each template as credentials.conf beneath the corresponding user-unit drop-in directory, then run systemctl --user daemon-reload. Restart only the affected units and verify their effective EnvironmentFiles and loaded code paths. Do not inspect Environment or print file contents as verification.
The Jetstream compartment intentionally carries no model or Telegram credential. It is activatable only with a producer-only Jetstream command. This slice is based on d7abc76, whose Jetstream command also starts consumers; producer-only support must exist in the target branch before installing this drop-in or enabling Jetstream.