feat: configure workspace runtime secrets through API

This commit is contained in:
2026-08-14 17:30:35 +02:00
parent 2114c94704
commit 87cefd120c
7 changed files with 325 additions and 41 deletions
+11 -1
View File
@@ -21,6 +21,7 @@ import {
type WorkspaceDescriptor,
} from "../workspaces/schema.js";
import { reconcileCollection } from "../workspaces/qdrant-collection.js";
import type { WorkspaceSecretStore } from "../workspaces/secret-store.js";
export interface ThtConfig extends SecretBundleConfig {
thtBin: string;
@@ -33,6 +34,7 @@ export interface ThtConfig extends SecretBundleConfig {
qdrantRequest?: typeof fetch;
/** "self_heal" for session admission (create missing collections/indexes), default "require_existing". */
qdrantCollectionMode?: "self_heal" | "require_existing";
workspaceSecretStore?: WorkspaceSecretStore;
}
export interface RuntimeConfigLease {
@@ -221,8 +223,15 @@ export class ThtRunner {
})(),
secretRoots: this.cfg.secretRoots ?? [],
semanticRuntime: this.cfg.semanticRuntime ?? DEFAULT_SEMANTIC_RUNTIME,
workspaceSecretStore: this.cfg.workspaceSecretStore,
});
const path = this.createRuntimeSnapshot(rendered.renderedConfig);
let path: string;
try {
path = this.createRuntimeSnapshot(rendered.renderedConfig);
} catch (error) {
rendered.releaseSecrets();
throw error;
}
let released = false;
return {
path,
@@ -232,6 +241,7 @@ export class ThtRunner {
if (released) return;
released = true;
this.cleanupRuntimeSnapshot(path);
rendered.releaseSecrets();
},
};
}