#!/usr/bin/env bash # Query the pinned batch API over LAN TLS without cluster or Vault credentials. set -euo pipefail if [[ ${1:-} == --help ]]; then cat <<'USAGE' Usage: HERMES_LAN_TOKEN_FILE=/private/token hermes_batch_curl.sh --models HERMES_LAN_TOKEN_FILE=/private/token hermes_batch_curl.sh < request.json Generation input is the API request object, not the Python client's scope envelope. The roster application must first filter FA01 and permitted fields on the laptop. USAGE exit 0 fi if [[ $# -gt 1 || ( $# -eq 1 && $1 != --models ) ]]; then printf 'Only --models or a generation request on stdin is supported\n' >&2 exit 2 fi : "${HERMES_LAN_TOKEN_FILE:?Set HERMES_LAN_TOKEN_FILE to the private scoped token file}" umask 077 scratch=$(mktemp -d) trap 'rm -rf -- "$scratch"' EXIT token=$(cat -- "$HERMES_LAN_TOKEN_FILE") if [[ ! $token =~ ^[0-9a-f]{64}$ ]]; then printf 'Invalid LAN API credential\n' >&2 exit 1 fi printf 'header = "Authorization: Bearer %s"\n' "$token" > "$scratch/curl.conf" unset token arguments=(--fail-with-body --silent --show-error --connect-timeout 10 --max-time 1810 --noproxy worker.bstein.dev --resolve worker.bstein.dev:443:192.168.22.50 --config "$scratch/curl.conf" --header 'Content-Type: application/json') operation=models if [[ ${1:-} != --models ]]; then operation=generate cat > "$scratch/request.json" arguments+=(--data-binary "@$scratch/request.json") fi # No redirect following, automatic retry, or alternative destination. curl "${arguments[@]}" "https://worker.bstein.dev/local-model/api/batch/$operation"