feat(cli): validate prerequisites and seal installation plans

This commit is contained in:
Codex
2026-09-28 17:03:25 +02:00
parent b9c3369e7b
commit 55f3569e55
30 changed files with 2271 additions and 4 deletions
@@ -175,6 +175,11 @@ func Validate(path string) (config.Installation, Report) {
report.Add("operator.env", "$", "secret_references_invalid", "Use canonical absolute paths for all _FILE and _SOURCE references.")
}
for _, file := range files {
// The descriptor is a _SOURCE reference too, but its YAML values were already checked.
// Template instructions in comments are not unresolved credential placeholders.
if file == path {
continue
}
allowEmpty := file == value("THT_WORKSPACE_GIT_CREDENTIALS_FILE")
CheckSecret(file, "operator.env", "protected-file-reference", allowEmpty, &report)
}