Repository navigation
feat(secrets): credential consumption wiring onto main — source:credential, {{credential}} token, LLM-by-id (ADR-0031 Phase 2) - #91
Merged
Conversation
…al}} token, LLM-by-id (ADR-0031 Phase 2)
Wire the three credential reference forms, all resolving through the existing
environment-scoped secret resolver (a credential ref is sugar over the reserved
cred/<id>/<field> secret name):
- Input mapping source:"credential" (variable "<id>.<field>") resolves to a
redacted SecretValue (internal/workflow: SourceCredential + resolveCredential).
- {{credential:id.field}} tokens in schema string values resolve alongside
{{secret:NAME}} in resolveSchemaValue.
- LLM provider-by-credential: LLM_<PROVIDER>_CREDENTIAL=<id> supplies the
provider apiKey from the credential's apiKey field (per environment) when
API_KEY is unset; di/llm now resolves both secret and credential refs.
Also: `fuse secrets list` hides cred/* entries (managed via `fuse credentials`).
Refactor: extracted the SourceFlow branch of inputMapping into applyFlowMapping
to keep cyclomatic complexity within the limit.
Tests: workflow credential input-mapping + token resolution (redaction asserted);
di/llm credential-by-id resolves per environment / errors (no panic) when absent.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
PR #88 was merged into its stacked base (
feat/credentials-registry) rather thanmain, sothe credentials consumption wiring never reached
main— even though the credentials registryfoundation did (via #87). This re-applies #88's single commit cleanly on top of
main.Contents (ADR-0031 Phase 2, deliverable 3 — consumption)
source:"credential"(variable:"<id>.<field>") → redactedSecretValue.{{credential:id.field}}token resolution in schema string values.LLM_<PROVIDER>_CREDENTIAL=<id>supplies the providerapiKeyfromthe credential (per environment) when
API_KEYis unset.fuse secrets listhidescred/*entries.inputMapping'sSourceFlowbranch extracted intoapplyFlowMapping(complexity).All three reference forms resolve through the existing environment-scoped resolver via the reserved
cred/<id>/<field>namespace; every path yields a redactedSecretValue.Verification
make lint0 issues ·make buildok ·make test699 pass.🤖 Generated with Claude Code