LangGraph custom image: keep SUME_API_KEY out of it
langgraph-cli 0.4.32 adds an --image-uri flag for self-hosted custom containers. Inject SUME_API_KEY as a runtime env var; never bake it into the image.

When you build a custom container for a self-hosted LangGraph deployment, the Sume key belongs in the container's runtime environment, not in the image layers. The LangGraph releases page lists langgraph-cli 0.4.32 (Sep 23, 2026) with self-hosted deployment improvements, including an --image-uri flag for custom containers.
Why the image matters
An image is copied, pushed to registries and cached on build hosts. Anything written into it with ENV, ARG or a copied .env file travels with it. The Sume CLI security page says to never print or commit SUME_API_KEY, and to use environment variables or secret managers for automation.
Where each secret goes
| Item | In the image? | At runtime |
|---|---|---|
| Code and dependencies | Yes | n/a |
| SUME_API_KEY | No | Environment variable from a secret manager |
| SUME_COM_WEBHOOK_SIGNING_SECRET | No | Environment variable |
| Job ids and artifact URLs | No | Graph state or your own store |
Reading the key at runtime
Fail fast when the variable is missing, so a misconfigured deployment shows up on the first request rather than as a confusing 401 later.
import os
import requests
def sume_headers() -> dict:
key = os.environ.get("SUME_API_KEY", "")
if not key:
raise RuntimeError("SUME_API_KEY is not set in this container")
return {"Authorization": f"Bearer {key}"}
def job_status(job_id: str) -> dict:
r = requests.get(
f"https://api.sume.com/v1/jobs/{job_id}/status",
headers=sume_headers(),
timeout=30,
)
r.raise_for_status()
return r.json()Checklist
- No
ENV SUME_API_KEYorARG SUME_API_KEYin the Dockerfile. - Build with a clean context; exclude
.envand~/.sume-com/config.json. - Pass the key at deploy time from your platform's secret store.
- Keep keys out of logs and raw provider payloads out of bug reports.
- Rotate by creating a new key and retiring the old one.
Scope the key
Create a key at the API Keys dashboard for this service. Paid generation calls still need an Idempotency-Key, and a bounded first job is the safe way to test a new deployment.
Sources
Related posts
More in Developers
- Luma callback_url or polling: which Sume job mode matches
Luma's API docs list keyframes, loop and callback_url for ray-2. On Sume the equivalent choice is job mode: async, sync up to 30 s, subscribe or webhook.
- Luma API callback_url vs Sume callback_url: signing and retries
Luma's video API takes a callback_url, and so does Sume's /v1/videos. What Sume's callback is signed with, how often it retries, and a Python verifier.
- Luma callback: 3 retries, 5 s timeout, vs Sume webhooks
Luma retries a failed callback at most 3 times with a 5-second timeout. Sume retries job webhooks up to 10 times with a 10-second timeout and signs each body.
- MCP 2026-07-28 deprecations: SSE, sampling, roots, logging checklist
MCP 2026-07-28 deprecates Roots, Sampling and Logging and reclassifies HTTP+SSE as Deprecated, with 12 months of notice. A checklist for media servers.
Written by Sume