hanzo-dev b7438a849b
deploy / build (push) Successful in 5m33s
the ingest key was fetched, passed, and then erased by the Dockerfile
1.0.58 published a bundle with no key from a run in which every step was green:
the KMS step logged "ingest key resolved (40 chars)" and buildx ran with
`--build-arg EVENT_INGEST_KEY=***`. The image config it produced reads
`VITE_EVENT_INGEST_KEY=` — empty. 1.0.57, built before this file changed, reads
`VITE_EVENT_INGEST_KEY=pk-live-…`.

A second `ARG VITE_EVENT_INGEST_KEY=` had been added below the pair that sets it.
A build arg declared after an ENV of the same name shadows it for every later
expansion, so `ENV VITE_EVENT_INGEST_KEY=$VITE_EVENT_INGEST_KEY` read the empty
ARG default and overwrote the key. One name, declared twice, and the second
declaration won.

So: one declaration. EVENT_INGEST_KEY is the name in KMS and on the --build-arg;
the VITE_ prefix is applied once, here, because the prefix is a property of this
build and not of the secret.

Two gates, because nothing between the secret store and the browser had noticed:

  - The Dockerfile now asserts the key it was given is actually present in
    client/dist. `pnpm run frontend` is what inlines it, so that is the first
    moment the question can be answered and the last moment it is cheap. An
    absent key is only warned about — this image is also built without the
    credential — but a key that was supplied and did not reach the artifact
    fails the build. The value is never echoed.

  - deploy.yml's KMS step now fails the build, with a reason. Its `exit 0`
    guards had never run: the runner invokes `run:` under `bash -e`, so the
    first curl returning >= 400 aborted the step first. That is how run 7 — the
    commit that added the key — died as a bare `exitcode '22'` and left main
    looking fixed with no image to show for it. Each curl is now rescued so the
    guard decides, and each guard names which call failed.

hanzo.yml stops claiming to be what builds this repo. `.hanzo/workflows/deploy.yml`
is, run by the forge on the git-runner fleet; the `images:` block is read by
cloud's build_on_push, which these repos do not route through — no
`sha-<sha7>-amd64-chat` tag exists for any commit here. It is left as a
declaration of intent, with the warning that its enqueue body carries no
build-arg field and so cannot pass this credential at all.

Co-authored-by: Hanzo Dev <dev@hanzo.ai>
2026-08-04 00:01:25 -07:00
2026-07-26 16:16:16 -07:00
2025-07-16 15:26:20 -05:00
2023-08-31 16:58:54 -07:00
2024-10-23 15:44:27 +05:30
2025-06-30 10:45:37 -07:00
2026-02-19 20:36:08 -08:00
2025-07-01 17:24:11 -07:00

Hanzo Chat

Hanzo Chat

The chat surface of the Hanzo AI cloud: multi-model chat with agents, tools, and retrieval, running on Hanzo's backend. Live at hanzo.chat.

Hanzo Chat is a sibling to hanzo.app (the app builder) and the Hanzo console (admin). All inference, code execution, and web search route through the unified Hanzo API at api.hanzo.ai/v1, and sign-in is federated to Hanzo IAM (hanzo.id).

Features

  • Multi-model chat — the Zen model family and other frontier models, served through api.hanzo.ai.
  • Agents — build agents in the thread, or run your Hanzo Cloud agents (/v1/agents) with an /agent command or @mention.
  • MCP tools — connect Model Context Protocol servers for tool use.
  • RAG — chat over your own files and documents.
  • Web search — grounded answers via Hanzo web search.
  • Code interpreter — run code in a sandboxed runtime.
  • Image generation — generate images inline.
  • Guest chat — try a free Zen model with no account (optional, off by default).

Requirements

Quick start (Docker)

git clone https://github.com/hanzoai/chat.git
cd chat
cp .env.example .env        # set HANZO_API_KEY
make up

Open http://localhost:3080. make up starts the full stack (app, MongoDB, Meilisearch) from compose.yml; make down stops it.

Development

pnpm install               # install workspace dependencies
pnpm build:packages        # build the shared workspace packages
pnpm backend:dev           # API server on :3080 (nodemon)
pnpm frontend:dev          # Vite client dev server (second terminal)

Tests and checks:

pnpm test:all              # all workspace tests
pnpm e2e                   # Playwright end-to-end tests
pnpm lint                  # ESLint
pnpm format                # Prettier

Configuration

Secrets live in .env; the model catalog and endpoints live in chat.yaml (copy chat.example.yaml). Key variables:

HANZO_API_KEY=             # Hanzo API key — inference, tools, search
MONGO_URI=                 # MongoDB connection — chat history, users
JWT_SECRET=                # session token signing
CREDS_KEY=                 # credential encryption
CREDS_IV=

Sign-in is federated to Hanzo IAM over OpenID Connect (OPENID_ISSUER=https://hanzo.id, client hanzo-chat).

Workspace

api/           Express backend (:3080) — routes, controllers, Mongoose models
client/        React frontend (Vite)
packages/      data-provider · data-schemas · api · client · agents · mcp

Documentation

License

MIT. MIT licensed. See LICENSE for the full attribution.

S
Description
Hanzo tenant service — source mirrored from hanzoai/chat
Readme MIT
6.3 GiB
Languages
TypeScript 68%
JavaScript 22.1%
Python 6.7%
HTML 2.1%
CSS 0.4%
Other 0.6%