JuliusBrussee/caveman · error

auth_token: in is ignored — the inbound token is read only…

Error message

auth_token: in %s is ignored — the inbound token is read only from the CAVEMAN_AUTH_TOKEN environment variable; remove the key

What it means

The caveman.yaml loader (proxy/internal/config/config.go:173) refuses to start when the config file contains an auth_token key. Inbound authentication is deliberately read only from the CAVEMAN_AUTH_TOKEN environment variable so the secret never persists to disk; a token found in YAML is treated as a hard configuration error and the file's value is never echoed to the log.

Solutions

  1. Delete the auth_token key from caveman.yaml
  2. Export CAVEMAN_AUTH_TOKEN=<token> in the proxy's environment instead
  3. If you intentionally want no token, remove the key entirely rather than leaving it empty-stringed only if your YAML parser keeps it — ensure the parsed value is empty
  4. Update provisioning scripts/templates so they inject the env var, not the YAML key

Example fix

// before (caveman.yaml)
listen: 127.0.0.1:8080
auth_token: sk-secret-123
// after (caveman.yaml)
listen: 127.0.0.1:8080
# shell: export CAVEMAN_AUTH_TOKEN=sk-secret-123
Defensive patterns

Strategy: validation

Validate before calling

func assertNoAuthTokenInYAML(t string) error {
    var m map[string]any
    if err := yaml.Unmarshal([]byte(t), &m); err != nil { return err }
    if _, ok := m["auth_token"]; ok {
        return errors.New("remove auth_token from caveman.yaml; use CAVEMAN_AUTH_TOKEN env")
    }
    return nil
}

Try / catch

if _, err := config.Load(path); err != nil {
    if strings.Contains(err.Error(), "auth_token:") {
        logger.Error("config rejected: auth_token key present; use CAVEMAN_AUTH_TOKEN env var instead")
        os.Exit(1)
    }
    return err
}

Prevention

When it happens

Trigger: Running 'caveman-proxy serve' (or status, via Load) with a caveman.yaml that has an auth_token: line — typically written by hand or by an older workflow — triggers this fail-fast error before the listener starts.

Common situations: Migrating from a version/agent that stored tokens in YAML; copying a config template that still lists auth_token; following outdated docs; a provisioning script writing secrets into the config file.

Related errors


AI-assisted analysis of JuliusBrussee/caveman@3ee70a1026 (2026-09-20). Data as JSON: /api/errors/1b74531487d6a186. Report an issue: GitHub.

Appendix: source

Thrown at proxy/internal/config/config.go:173

// default config (record mode on 127.0.0.1:8787) rather than an error: a bare
// `caveman start` with no config file is a valid record-only session.
func Load(path string) (Config, error) {
	cfg := Config{}
	raw, err := os.ReadFile(path)
	switch {
	case os.IsNotExist(err):
		// no file — defaults only
	case err != nil:
		return cfg, err
	default:
		if err := yaml.Unmarshal(raw, &cfg); err != nil {
			return cfg, err
		}
	}
	if strings.TrimSpace(cfg.AuthTokenYAML) != "" {
		// Never echo the value: it reached a file on disk, but this error reaches
		// the proxy log.
		return Config{}, fmt.Errorf("auth_token: in %s is ignored — the inbound token is read only from the CAVEMAN_AUTH_TOKEN environment variable; remove the key", path)
	}
	cfg = cfg.withDefaults()
	if err := validateAuthToken(cfg.AuthToken); err != nil {
		return Config{}, err
	}
	if err := validateListen(cfg.Listen, cfg.AuthToken != ""); err != nil {
		return Config{}, err
	}
	if err := cfg.validateCompat(); err != nil {
		return Config{}, err
	}
	proxyFunc, err := parseUpstreamProxy(cfg.UpstreamProxy)
	if err != nil {
		return Config{}, err
	}
	cfg.upstreamProxy, cfg.upstreamProxyParsed = proxyFunc, true
	if err := cfg.loadRootCAs(); err != nil {
		return Config{}, err

View on GitHub (pinned to 3ee70a1026)