fix: gate workspace diagnostic migration

This commit is contained in:
2026-08-03 23:30:15 +02:00
parent c5685f4962
commit 450d7ab07f
14 changed files with 430 additions and 145 deletions
+5 -4
View File
@@ -5,9 +5,9 @@ import {
DWH_TRANSPORTS,
VECTOR_TRANSPORTS,
validateCanonicalWorkspace,
type CanonicalWorkspace,
type DwhTransport,
type VectorTransport,
type WorkspaceDescriptor,
} from "./schema.js";
export interface ResolvedBinding {
@@ -63,10 +63,11 @@ function isSafeSecretFile(path: string, secretRoots: readonly string[]): boolean
}
function requiredSuffixes(
role: Exclude<InstallationRole, "VECTOR_WRITER">,
role: InstallationRole,
transport: DwhTransport | VectorTransport,
): readonly InstallationSuffix[] {
if (role === "EMBEDDING") return EMBEDDING_REQUIRED_SUFFIXES;
if (role === "VECTOR_WRITER") return ["API_KEY_FILE"];
return REQUIRED_SUFFIXES[role][transport] ?? [];
}
@@ -75,8 +76,8 @@ function requiredSuffixes(
* deliberately left for the harness secret-file loader, so bindings cannot leak credentials.
*/
export function resolveBinding(
workspace: CanonicalWorkspace,
role: Exclude<InstallationRole, "VECTOR_WRITER">,
workspace: WorkspaceDescriptor,
role: InstallationRole,
env: NodeJS.ProcessEnv,
secretRoots: readonly string[],
): ResolvedBinding {