Skip to content

feat(secrets): credential consumption wiring onto main — source:credential, {{credential}} token, LLM-by-id (ADR-0031 Phase 2) - #91

Merged
gustavobertoi merged 2 commits into
mainfrom
fix/credentials-consumption-to-main
Jun 3, 2026
Merged

gustavobertoi merged 2 commits into
mainfrom
fix/credentials-consumption-to-main

Conversation

@gustavobertoi

Copy link
Copy Markdown
Collaborator

Why

PR #88 was merged into its stacked base (feat/credentials-registry) rather than main, so
the credentials consumption wiring never reached main — even though the credentials registry
foundation did (via #87). This re-applies #88's single commit cleanly on top of main.

Cherry-pick of 4720ecc onto current main (which already has the registry foundation from
#87). No new code vs the already-reviewed #88.

Contents (ADR-0031 Phase 2, deliverable 3 — consumption)

  • Input mapping source:"credential" (variable:"<id>.<field>") → redacted SecretValue.
  • {{credential:id.field}} token resolution in schema string values.
  • LLM provider-by-credential: LLM_<PROVIDER>_CREDENTIAL=<id> supplies the provider apiKey from
    the credential (per environment) when API_KEY is unset.
  • fuse secrets list hides cred/* entries.
  • Refactor: inputMapping's SourceFlow branch extracted into applyFlowMapping (complexity).

All three reference forms resolve through the existing environment-scoped resolver via the reserved
cred/<id>/<field> namespace; every path yields a redacted SecretValue.

Verification

make lint 0 issues · make build ok · make test 699 pass.

🤖 Generated with Claude Code

…al}} token, LLM-by-id (ADR-0031 Phase 2)

Wire the three credential reference forms, all resolving through the existing
environment-scoped secret resolver (a credential ref is sugar over the reserved
cred/<id>/<field> secret name):

- Input mapping source:"credential" (variable "<id>.<field>") resolves to a
  redacted SecretValue (internal/workflow: SourceCredential + resolveCredential).
- {{credential:id.field}} tokens in schema string values resolve alongside
  {{secret:NAME}} in resolveSchemaValue.
- LLM provider-by-credential: LLM_<PROVIDER>_CREDENTIAL=<id> supplies the
  provider apiKey from the credential's apiKey field (per environment) when
  API_KEY is unset; di/llm now resolves both secret and credential refs.

Also: `fuse secrets list` hides cred/* entries (managed via `fuse credentials`).
Refactor: extracted the SourceFlow branch of inputMapping into applyFlowMapping
to keep cyclomatic complexity within the limit.

Tests: workflow credential input-mapping + token resolution (redaction asserted);
di/llm credential-by-id resolves per environment / errors (no panic) when absent.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gustavobertoi
gustavobertoi merged commit 6586c81 into main Jun 3, 2026
5 checks passed
@gustavobertoi
gustavobertoi deleted the fix/credentials-consumption-to-main branch June 4, 2026 06:19

This branch was previously deployed

1 inactive deployment
prod — e24ea62b Deployed Jun 3, 2026 by gustavobertoi via pr-image #314
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant