Files
hermes-agent/agent
beardthelion 6087b40932 fix(agent): refuse ambient credential chains for multiplex profiles
Under gateway multiplexing, a served profile with no credential of its own
fell through to the SDKs' ambient default chains, which read the process
environment — the launch profile's Azure service principal, az CLI caches,
host managed identity, or AWS keys — and the minted identity rode the served
profile's configured base_url. vertex_adapter already refuses the same
pattern for google.auth.default().

azure_identity_adapter._scoped_credential now raises under multiplexing
when the profile scope has no complete AZURE_* set; AZURE_CLIENT_ID alone
routes to ManagedIdentityCredential as the explicit user-assigned-MI
opt-in. _probe_token propagates the caller's contextvars into its daemon
thread so doctor/probe checks run scoped (a bare Thread ran unscoped and
masked the refusal). describe_active_credential reads all credential
predicates through the scope.

bedrock_adapter.scoped_aws_session_kwargs now requires a complete
credential under multiplexing (key pair, or AWS_PROFILE as the shared-
config opt-in) instead of returning {} and letting boto3.Session() resolve
the ambient chain; the guard runs before the boto3 import at both call
sites. resolve_bedrock_bearer_token reads AWS_BEARER_TOKEN_BEDROCK through
the profile scope under a HERMES_HOME override.
2026-09-20 12:09:47 -07:00
..
…
…