Skip to content
This repository was archived by the owner on Oct 3, 2026. It is now read-only.

chore(secrets): load local next dev through Varlock - #43

Closed
WalksWithASwagger wants to merge 2 commits into
mainfrom
cursor/varlock-local-dev-6d25
Closed

WalksWithASwagger wants to merge 2 commits into
mainfrom
cursor/varlock-local-dev-6d25

Conversation

@WalksWithASwagger

@WalksWithASwagger WalksWithASwagger commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Summary

Repo-side finish for the kk-kb secrets plan Step 7, group A (wedges only). Local next dev now loads env through Varlock. Deployed values stay in Vercel. This PR does not merge, does not change repo settings, and does not remove any local symlink.

Convention sources: WalksWithASwagger/kk-kb docs/AGENT-SECRETS-VARLOCK.md, meta/plans/2026-09-24-portfolio-and-secrets-workplan.md (rules + Step 7). Pattern: WalksWithASwagger/bcai-website#3100 and WalksWithASwagger/futureproof-festival#2556.

  • .env.schema still pick-imports only ANTHROPIC_API_KEY from ~/.agents/env/values/.env.shared.local.
  • It now @imports the project values file ~/.agents/env/values/.env.wedges.local by path, with no pick list and allowMissing=true.
  • npm run dev runs next dev through varlock run --inject vars. npm run env:validate is the redacted load.
  • npm run build and npm run start are unchanged. The Varlock Next.js integration is not used: it overrides @next/env and bakes resolved env into the Vercel build, which this step must not touch.
  • varlock@^1.21.0 is a new devDependency so the local CLI matches the lockfile.
  • No value file was opened, created, or committed. Key names only.

Related Issues

Refs WalksWithASwagger/kk-kb#3751

No wedges issue. Do not invent one.

Acceptance Criteria

  • .env.schema @imports the project values file by path (allowMissing=true); shared import stays pick-restricted
  • Local next dev loads through varlock run (not the Next.js integration)
  • Vercel build / production env loading, vercel.json, and CI secrets are unchanged
  • Secret-free lint / typecheck / build still work without Varlock values
  • No local symlink deleted in this PR

Validation

Ran on this checkout with no Varlock value files present:

  • npm run env:validate — exit 0; missing imports allowed; redacted agent output only (no values)
  • npx varlock run --inject vars -- /usr/bin/true — exit 0
  • npm test — 52 passed, 0 failed (includes the new Varlock contract test)
  • npm run lint — pass
  • npm run typecheck — pass
  • npm run build — pass (Next.js 16.2.9; no Varlock wrap)
  • CI on this PR — all 5 checks green (Verify / verify, Vercel, Vercel Preview Comments, Cursor Approval Agent, Cursor Security Agent)

npm run test:browser was not run locally (Playwright browsers; CI owns that job and it passed). No UI, route, or production env change.

Schema keys (names only)

ANTHROPIC_API_KEY, ANTHROPIC_MODEL, KV_REST_API_TOKEN, KV_REST_API_URL, NODE_ENV, UPSTASH_REDIS_REST_TOKEN, UPSTASH_REDIS_REST_URL, WEDGES_URL

Changelog

  • Changelog: developer-facing local-dev wiring only; no production behavior change

Local step for KK

Do this on the Mac. Do not do it from CI or a cloud agent. Do not open, copy, or hash any value file.

  1. Before. In ~/Code/wedges on current main:

    npx varlock load --agent --show-all

    If Varlock is not installed on that checkout yet, use the standalone CLI the same way you do for other repos. Keep the redacted output (names and validation shape only).

  2. Confirm which app-local env paths are symlinks into ~/.agents/env/values/:

    ls -l .env .env.local .env.development.local

    Only a symlink is a candidate to remove later. If ls -l shows a regular file, stop and leave it.

  3. Check out this branch (or main after merge). npm ci then npm run dev now injects through Varlock. You do not need varlock run --inject vars -- npm run dev anymore.

  4. Smoke the same local integrations you already use (browser review / MCP critique / Film Club Redis as applicable).

  5. After that smoke is good, remove only the symlink(s) confirmed in step 2. Typical command, only if ls -l showed a symlink:

    rm .env.local

    Repeat for any other confirmed symlink (.env, .env.development.local). Do not delete ~/.agents/env/values/.env.wedges.local or .env.shared.local.

  6. After.

    npm run env:validate

    That is varlock load --agent --show-all. Compare to step 1. Names and redacted shape should match. Then confirm npm run dev still has the same provider-backed behavior with the symlink gone.

Live-Site Rollback

No live-site mutation. Revert this PR (or git revert the merge) to restore the pick-only project import and unwrapped next dev. Vercel env is untouched, so production rollback is the git revert only.

Risk Notes

  • varlock run --inject vars on npm run dev injects resolved schema items into the Next child process. After the Mac symlink is removed, values come only from the @imported project file. If that file is missing or fails type checks, local provider flows fail closed; secret-free next dev still starts because items are optional / allowMissing=true.
  • Build and start stay on native Next env loading so Vercel next build does not require Varlock values.
Open in Web Open in Cursor 

Import ~/.agents/env/values/.env.wedges.local by path and run next dev
through varlock run so local values no longer depend on a repo-root
.env symlink. Leave next build and Vercel unwired.

Co-authored-by: Kris Krüg <WalksWithASwagger@users.noreply.github.com>
@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
wedges Ready Ready Preview Sep 29, 2026 2:15am UTC

Request Review

Named regex groups fail tsc under the repo target. Changelog now
points at PR 43.

Co-authored-by: Kris Krüg <WalksWithASwagger@users.noreply.github.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Cursor Bugbot was not present after the first check poll, so that signal was skipped, and no approval policy required human review. No reviewers were assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@WalksWithASwagger

Copy link
Copy Markdown
Owner Author

Closing: this change landed in kk-kb via https://github.com/WalksWithASwagger/kk-kb/pull/4127 (apps/wedges), where the app now lives.

This branch was successfully deployed

1 active deployment
Preview — 89e64ed2 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants