Credential Rotation Checklist¶
Every item below was exposed in Git history by agent sessions. All must be rotated at the provider, not just removed from source.
1. blu-chat — .env.production keys¶
- Bead: ESC-1
- Repo:
blu-chat - What: Real API keys committed in
.env.production - Action: Go to each provider dashboard, revoke the old key, generate a new one, store the new reference in 1Password.
2. agent-router — .env.litellm keys¶
- Bead: ESC-2
- Repo:
agent-router(insideagent-docker) - What: LiteLLM provider API keys pushed to Git
- Action: Revoke at each provider (Anthropic / OpenAI / whichever keys were in that file), generate replacements, update 1Password references.
3. GitLab PAT — bluefly-drupal-agent¶
- Bead:
bc-31a2 - What: A GitLab personal access token was embedded in a
https://<user>:<token>@gitlab...Git URL in CLI history/logs. - Action: GitLab → Settings → Access Tokens → Revoke the
bluefly-drupal-agenttoken → Create replacement → Update 1Password reference.
4. blu_fleet API token¶
- Bead:
bc-0pqi - Repo:
contextcontrol-ai(config/sync) - What:
blu_fleetAPI token committed to source. - Action: Revoke/regenerate the
blu_fleettoken at the issuing service, update 1Password reference.
5. Google API key¶
- Bead:
bc-4w9a - Repo:
bluefly-ioorcontextcontrol-ai(config/sync) - What: Google Fonts / Google API key committed to source.
- Action: Google Cloud Console → APIs & Services → Credentials → Delete the exposed key → Create replacement → Update 1Password reference.
After Each Rotation¶
- Verify the NEW credential works (test an API call or git clone).
- Verify the OLD credential is rejected.
- Update the 1Password item so
op://references resolve to the new value. - Confirm no
.envfiles with resolved values remain in any tracked branch.