LangGraph custom image: keep SUME_API_KEY out of it

langgraph-cli 0.4.32 adds an --image-uri flag for self-hosted custom containers. Inject SUME_API_KEY as a runtime env var; never bake it into the image.

4 min readSume
All posts

When you build a custom container for a self-hosted LangGraph deployment, the Sume key belongs in the container's runtime environment, not in the image layers. The LangGraph releases page lists langgraph-cli 0.4.32 (Sep 23, 2026) with self-hosted deployment improvements, including an --image-uri flag for custom containers.

Why the image matters

An image is copied, pushed to registries and cached on build hosts. Anything written into it with ENV, ARG or a copied .env file travels with it. The Sume CLI security page says to never print or commit SUME_API_KEY, and to use environment variables or secret managers for automation.

Where each secret goes

Secrets and the container (LangGraph releases and Sume docs, read 2026-10-03)
ItemIn the image?At runtime
Code and dependenciesYesn/a
SUME_API_KEYNoEnvironment variable from a secret manager
SUME_COM_WEBHOOK_SIGNING_SECRETNoEnvironment variable
Job ids and artifact URLsNoGraph state or your own store

Reading the key at runtime

Fail fast when the variable is missing, so a misconfigured deployment shows up on the first request rather than as a confusing 401 later.

import os
import requests

def sume_headers() -> dict:
    key = os.environ.get("SUME_API_KEY", "")
    if not key:
        raise RuntimeError("SUME_API_KEY is not set in this container")
    return {"Authorization": f"Bearer {key}"}

def job_status(job_id: str) -> dict:
    r = requests.get(
        f"https://api.sume.com/v1/jobs/{job_id}/status",
        headers=sume_headers(),
        timeout=30,
    )
    r.raise_for_status()
    return r.json()

Checklist

  • No ENV SUME_API_KEY or ARG SUME_API_KEY in the Dockerfile.
  • Build with a clean context; exclude .env and ~/.sume-com/config.json.
  • Pass the key at deploy time from your platform's secret store.
  • Keep keys out of logs and raw provider payloads out of bug reports.
  • Rotate by creating a new key and retiring the old one.

Scope the key

Create a key at the API Keys dashboard for this service. Paid generation calls still need an Idempotency-Key, and a bounded first job is the safe way to test a new deployment.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume