Peter Steinberger
|
c89836a251
|
test: harden flaky timeout and resolver specs
|
2026-03-01 21:30:07 +00:00 |
|
Peter Steinberger
|
262bca9bdd
|
fix: restore dm command and self-chat auth behavior
|
2026-02-26 18:49:16 +01:00 |
|
Peter Steinberger
|
47fc6a0806
|
fix: stabilize secrets land + docs note (#26155) (thanks @joshavant)
|
2026-02-26 14:47:22 +00:00 |
|
Peter Steinberger
|
820d614757
|
fix(secrets): harden plan target paths and ref-only auth profiles
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
485cd0c512
|
fix(test): skip exec-backed audit batching assertion on windows
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
7671c1dd10
|
test(secrets): cover skill migration and symlinked exec command flow
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
d879c7c641
|
fix(secrets): harden apply and audit plan handling
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
f46b9c996f
|
feat(secrets): allow opt-in symlink exec command paths
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
06290b49b2
|
feat(secrets): finalize mode rename and validated exec docs
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
ba2eb583c0
|
fix(secrets): make apply idempotent and keep audit read-only
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
f413e314b9
|
feat(secrets): replace migrate flow with audit/configure/apply
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
8944b75e16
|
fix(secrets): align ref contracts and non-interactive ref persistence
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
86622ebea9
|
fix(secrets): enforce file provider read timeouts
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
060ede8aaa
|
test(secrets): skip windows ACL-sensitive file-provider runtime tests
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
b84d7796be
|
test(secrets): skip strict file-permission resolver tests on windows
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
bde9cbb058
|
docs(secrets): align provider model and add exec resolver coverage
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
4e7a833a24
|
feat(security): add provider-based external secrets management
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
bb60cab76d
|
test: sops invocation assertion
Signed-off-by: joshavant <830519+joshavant@users.noreply.github.com>
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
e8637c79b3
|
fix(secrets): harden sops migration sops rule matching
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
0e69660c41
|
feat(secrets): finalize external secrets runtime and migration hardening
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
4d94b05ac5
|
Secrets: keep read-only runtime sync in-memory
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
04aa856fc0
|
Onboard: require explicit mode for env secret refs
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
363334253b
|
Secrets migrate: split plan/apply/backup modules
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
8e439e2d81
|
Secrets migrate: ensure unique backup ids per write
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
a74067d00b
|
Secrets migrate: share helpers and narrow env scrub scope
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
f6a854bd37
|
Secrets: add migrate rollback and skill ref support
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
45ec5aaf2b
|
Secrets: keep read-only runtime sync in-memory
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
8e33ebe471
|
Secrets: make runtime activation auth loads read-only
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
e45729a430
|
Secrets runtime: include sourceConfig in prepared snapshot type
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
e4915cb107
|
Secrets: preserve runtime snapshot source refs on write
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
b50c4c2c44
|
Gateway: add eager secrets runtime snapshot activation
|
2026-02-26 14:47:22 +00:00 |
|