From d1b160310f680f6c19e63dd8cd492847c66ce684 Mon Sep 17 00:00:00 2001 From: Yuneng Jiang Date: Mon, 21 Sep 2026 14:27:29 -0700 Subject: [PATCH] fix(docker): require a generated master key in the quickstart stack The committed sk-1234 placeholder is in PUBLICLY_KNOWN_MASTER_KEYS, so once an image ships fe480533e8 the proxy refuses to boot and the quickstart stops working. It also meant the documented stack came up on port 4000 with a credential anyone could guess. Both keys now come from .env and compose refuses to render without them. The salt key is generated alongside so it stays stable across restarts, which keeps stored credentials readable. Verified: no .env -> compose fails closed naming the missing variable; with a generated .env the stack is healthy, /v1/models returns 200 for the generated key, 401 for sk-1234 and 401 unauthenticated, /ui/ serves, and the key still works after a restart. --- docker/README.md | 1 + docker/docker-compose.quickstart.yml | 11 ++++++----- 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/docker/README.md b/docker/README.md index 787866ce35a..376dc7b2d97 100644 --- a/docker/README.md +++ b/docker/README.md @@ -9,6 +9,7 @@ This guide provides instructions for building and running the LiteLLM applicatio > > ```bash > curl -sSLO https://github.com/BerriAI/litellm/raw/main/docker/docker-compose.quickstart.yml +> printf 'LITELLM_MASTER_KEY=sk-%s\nLITELLM_SALT_KEY=sk-%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env > docker compose -f docker-compose.quickstart.yml up -d > ``` diff --git a/docker/docker-compose.quickstart.yml b/docker/docker-compose.quickstart.yml index 7c849c759f0..11631603a72 100644 --- a/docker/docker-compose.quickstart.yml +++ b/docker/docker-compose.quickstart.yml @@ -3,19 +3,20 @@ # https://docs.litellm.ai/docs/proxy/docker_quick_start # # curl -sSLO https://github.com/BerriAI/litellm/raw/main/docker/docker-compose.quickstart.yml +# printf 'LITELLM_MASTER_KEY=sk-%s\nLITELLM_SALT_KEY=sk-%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env # docker compose -f docker-compose.quickstart.yml up -d # -# The credentials below are placeholders for local evaluation. Before any real -# use, set LITELLM_MASTER_KEY and LITELLM_SALT_KEY to long random values and -# pin the image to a specific release tag. +# Compose reads .env from this directory. Keep it: regenerating LITELLM_SALT_KEY +# makes credentials already stored in the database unreadable. For anything +# beyond local evaluation, pin the image to a specific release tag. services: litellm: image: docker.litellm.ai/berriai/litellm:main-stable ports: - "4000:4000" environment: - LITELLM_MASTER_KEY: sk-1234 - LITELLM_SALT_KEY: sk-XXXXXXXXXXXXXXXX + LITELLM_MASTER_KEY: ${LITELLM_MASTER_KEY:?set it in .env - see the header of this file} + LITELLM_SALT_KEY: ${LITELLM_SALT_KEY:?set it in .env - see the header of this file} DATABASE_URL: postgresql://litellm:litellm@db:5432/litellm STORE_MODEL_IN_DB: "True" depends_on: