JuliusBrussee/caveman · error
auth_token: in is ignored — the inbound token is read only…
Error message
auth_token: in %s is ignored — the inbound token is read only from the CAVEMAN_AUTH_TOKEN environment variable; remove the key
What it means
The caveman.yaml loader (proxy/internal/config/config.go:173) refuses to start when the config file contains an auth_token key. Inbound authentication is deliberately read only from the CAVEMAN_AUTH_TOKEN environment variable so the secret never persists to disk; a token found in YAML is treated as a hard configuration error and the file's value is never echoed to the log.
Solutions
- Delete the auth_token key from caveman.yaml
- Export CAVEMAN_AUTH_TOKEN=<token> in the proxy's environment instead
- If you intentionally want no token, remove the key entirely rather than leaving it empty-stringed only if your YAML parser keeps it — ensure the parsed value is empty
- Update provisioning scripts/templates so they inject the env var, not the YAML key
Example fix
// before (caveman.yaml) listen: 127.0.0.1:8080 auth_token: sk-secret-123 // after (caveman.yaml) listen: 127.0.0.1:8080 # shell: export CAVEMAN_AUTH_TOKEN=sk-secret-123
Defensive patterns
Strategy: validation
Validate before calling
func assertNoAuthTokenInYAML(t string) error {
var m map[string]any
if err := yaml.Unmarshal([]byte(t), &m); err != nil { return err }
if _, ok := m["auth_token"]; ok {
return errors.New("remove auth_token from caveman.yaml; use CAVEMAN_AUTH_TOKEN env")
}
return nil
} Try / catch
if _, err := config.Load(path); err != nil {
if strings.Contains(err.Error(), "auth_token:") {
logger.Error("config rejected: auth_token key present; use CAVEMAN_AUTH_TOKEN env var instead")
os.Exit(1)
}
return err
} Prevention
- Never write secrets into caveman.yaml; inject CAVEMAN_AUTH_TOKEN via the environment
- Lint config templates for an auth_token key in CI
- Update old provisioning scripts that predate the env-only rule
When it happens
Trigger: Running 'caveman-proxy serve' (or status, via Load) with a caveman.yaml that has an auth_token: line — typically written by hand or by an older workflow — triggers this fail-fast error before the listener starts.
Common situations: Migrating from a version/agent that stored tokens in YAML; copying a config template that still lists auth_token; following outdated docs; a provisioning script writing secrets into the config file.
Related errors
- Aider config has duplicate openai-api-base keys; refusing…
- Aider config has duplicate read keys; refusing unsafe merge
- Aider config uses inline/scalar read; use block-list form…
- caveman build: config must use strict lock and required…
- compat upstream forward_headers
AI-assisted analysis of JuliusBrussee/caveman@3ee70a1026 (2026-09-20).
Data as JSON: /api/errors/1b74531487d6a186.
Report an issue: GitHub.
Appendix: source
Thrown at proxy/internal/config/config.go:173
// default config (record mode on 127.0.0.1:8787) rather than an error: a bare
// `caveman start` with no config file is a valid record-only session.
func Load(path string) (Config, error) {
cfg := Config{}
raw, err := os.ReadFile(path)
switch {
case os.IsNotExist(err):
// no file — defaults only
case err != nil:
return cfg, err
default:
if err := yaml.Unmarshal(raw, &cfg); err != nil {
return cfg, err
}
}
if strings.TrimSpace(cfg.AuthTokenYAML) != "" {
// Never echo the value: it reached a file on disk, but this error reaches
// the proxy log.
return Config{}, fmt.Errorf("auth_token: in %s is ignored — the inbound token is read only from the CAVEMAN_AUTH_TOKEN environment variable; remove the key", path)
}
cfg = cfg.withDefaults()
if err := validateAuthToken(cfg.AuthToken); err != nil {
return Config{}, err
}
if err := validateListen(cfg.Listen, cfg.AuthToken != ""); err != nil {
return Config{}, err
}
if err := cfg.validateCompat(); err != nil {
return Config{}, err
}
proxyFunc, err := parseUpstreamProxy(cfg.UpstreamProxy)
if err != nil {
return Config{}, err
}
cfg.upstreamProxy, cfg.upstreamProxyParsed = proxyFunc, true
if err := cfg.loadRootCAs(); err != nil {
return Config{}, errView on GitHub (pinned to 3ee70a1026)