This repository was archived by the owner on Oct 3, 2026. It is now read-only.
Repository navigation
chore(secrets): load local next dev through Varlock - #43
Closed
WalksWithASwagger wants to merge 2 commits into
Closed
WalksWithASwagger wants to merge 2 commits into
WalksWithASwagger wants to merge 2 commits into
Conversation
Import ~/.agents/env/values/.env.wedges.local by path and run next dev through varlock run so local values no longer depend on a repo-root .env symlink. Leave next build and Vercel unwired. Co-authored-by: Kris Krüg <WalksWithASwagger@users.noreply.github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Named regex groups fail tsc under the repo target. Changelog now points at PR 43. Co-authored-by: Kris Krüg <WalksWithASwagger@users.noreply.github.com>
Owner
Author
|
Closing: this change landed in kk-kb via https://github.com/WalksWithASwagger/kk-kb/pull/4127 (apps/wedges), where the app now lives. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
Repo-side finish for the kk-kb secrets plan Step 7, group A (
wedgesonly). Localnext devnow loads env through Varlock. Deployed values stay in Vercel. This PR does not merge, does not change repo settings, and does not remove any local symlink.Convention sources:
WalksWithASwagger/kk-kbdocs/AGENT-SECRETS-VARLOCK.md,meta/plans/2026-09-24-portfolio-and-secrets-workplan.md(rules + Step 7). Pattern: WalksWithASwagger/bcai-website#3100 and WalksWithASwagger/futureproof-festival#2556..env.schemastill pick-imports onlyANTHROPIC_API_KEYfrom~/.agents/env/values/.env.shared.local.@imports the project values file~/.agents/env/values/.env.wedges.localby path, with no pick list andallowMissing=true.npm run devrunsnext devthroughvarlock run --inject vars.npm run env:validateis the redacted load.npm run buildandnpm run startare unchanged. The Varlock Next.js integration is not used: it overrides@next/envand bakes resolved env into the Vercel build, which this step must not touch.varlock@^1.21.0is a new devDependency so the local CLI matches the lockfile.Related Issues
Refs WalksWithASwagger/kk-kb#3751
No wedges issue. Do not invent one.
Acceptance Criteria
.env.schema@imports the project values file by path (allowMissing=true); shared import stays pick-restrictednext devloads throughvarlock run(not the Next.js integration)vercel.json, and CI secrets are unchangedValidation
Ran on this checkout with no Varlock value files present:
npm run env:validate— exit 0; missing imports allowed; redacted agent output only (no values)npx varlock run --inject vars -- /usr/bin/true— exit 0npm test— 52 passed, 0 failed (includes the new Varlock contract test)npm run lint— passnpm run typecheck— passnpm run build— pass (Next.js 16.2.9; no Varlock wrap)Verify / verify, Vercel, Vercel Preview Comments, Cursor Approval Agent, Cursor Security Agent)npm run test:browserwas not run locally (Playwright browsers; CI owns that job and it passed). No UI, route, or production env change.Schema keys (names only)
ANTHROPIC_API_KEY,ANTHROPIC_MODEL,KV_REST_API_TOKEN,KV_REST_API_URL,NODE_ENV,UPSTASH_REDIS_REST_TOKEN,UPSTASH_REDIS_REST_URL,WEDGES_URLChangelog
Local step for KK
Do this on the Mac. Do not do it from CI or a cloud agent. Do not open, copy, or hash any value file.
Before. In
~/Code/wedgeson currentmain:If Varlock is not installed on that checkout yet, use the standalone CLI the same way you do for other repos. Keep the redacted output (names and validation shape only).
Confirm which app-local env paths are symlinks into
~/.agents/env/values/:Only a symlink is a candidate to remove later. If
ls -lshows a regular file, stop and leave it.Check out this branch (or
mainafter merge).npm cithennpm run devnow injects through Varlock. You do not needvarlock run --inject vars -- npm run devanymore.Smoke the same local integrations you already use (browser review / MCP critique / Film Club Redis as applicable).
After that smoke is good, remove only the symlink(s) confirmed in step 2. Typical command, only if
ls -lshowed a symlink:Repeat for any other confirmed symlink (
.env,.env.development.local). Do not delete~/.agents/env/values/.env.wedges.localor.env.shared.local.After.
That is
varlock load --agent --show-all. Compare to step 1. Names and redacted shape should match. Then confirmnpm run devstill has the same provider-backed behavior with the symlink gone.Live-Site Rollback
No live-site mutation. Revert this PR (or
git revertthe merge) to restore the pick-only project import and unwrappednext dev. Vercel env is untouched, so production rollback is the git revert only.Risk Notes
varlock run --inject varsonnpm run devinjects resolved schema items into the Next child process. After the Mac symlink is removed, values come only from the@imported project file. If that file is missing or fails type checks, local provider flows fail closed; secret-freenext devstill starts because items are optional /allowMissing=true.next builddoes not require Varlock values.