feat: configure workspace runtime secrets through API
This commit is contained in:
@@ -27,6 +27,8 @@ import {
|
||||
type CanonicalEffectiveConfig,
|
||||
} from "./effective-config.js";
|
||||
import { resolveRuntimeBindings, type RuntimeBindings } from "./bindings.js";
|
||||
import { resolveRuntimeBindingsWithWorkspaceSecrets } from "./secret-requirements.js";
|
||||
import type { WorkspaceSecretStore } from "./secret-store.js";
|
||||
import { GitWorkspaceRepository } from "./git-repository.js";
|
||||
import { WorkspaceRegistry } from "./registry.js";
|
||||
import {
|
||||
@@ -58,6 +60,7 @@ export interface RenderedWorkspaceRuntime {
|
||||
bindingDigest: string;
|
||||
renderedConfig: string;
|
||||
semanticQdrantUrl: string;
|
||||
releaseSecrets(): void;
|
||||
}
|
||||
|
||||
export interface ActiveRenderedWorkspaceRuntime extends RenderedWorkspaceRuntime {
|
||||
@@ -298,33 +301,49 @@ function renderWorkspaceRuntimeFromWorkspace(options: {
|
||||
dataRoot: string;
|
||||
secretRoots: readonly string[];
|
||||
semanticRuntime: SemanticRuntimeConfig;
|
||||
workspaceSecretStore?: WorkspaceSecretStore;
|
||||
}): RenderedWorkspaceRuntime {
|
||||
const bindings = resolveRuntimeBindings(options.workspace, process.env, options.secretRoots);
|
||||
const secretLease = options.workspaceSecretStore === undefined
|
||||
? undefined
|
||||
: resolveRuntimeBindingsWithWorkspaceSecrets(
|
||||
options.workspace,
|
||||
process.env,
|
||||
options.secretRoots,
|
||||
options.workspaceSecretStore,
|
||||
);
|
||||
const bindings = secretLease?.bindings
|
||||
?? resolveRuntimeBindings(options.workspace, process.env, options.secretRoots);
|
||||
const overlay = installationOverlay(options.harnessDir, options.configPath);
|
||||
const context: RuntimeRenderContext = {
|
||||
workspaceId: options.workspaceId,
|
||||
workspaceRevision: options.workspaceRevision,
|
||||
revisionContentRoot: options.revisionContentRoot,
|
||||
};
|
||||
return {
|
||||
workspace: options.workspace,
|
||||
workspaceId: options.workspaceId,
|
||||
workspaceRevision: options.workspaceRevision,
|
||||
revisionContentRoot: options.revisionContentRoot,
|
||||
runtimePaths: runtimePaths(options.dataRoot, options.workspaceId, options.workspaceRevision),
|
||||
installationOverlay: overlay,
|
||||
bindings,
|
||||
bindingDigest: stableBindingDigest(bindings),
|
||||
semanticQdrantUrl: options.semanticRuntime.internalQdrantUrl,
|
||||
renderedConfig: renderRuntimeConfig(
|
||||
options.workspace,
|
||||
try {
|
||||
return {
|
||||
workspace: options.workspace,
|
||||
workspaceId: options.workspaceId,
|
||||
workspaceRevision: options.workspaceRevision,
|
||||
revisionContentRoot: options.revisionContentRoot,
|
||||
runtimePaths: runtimePaths(options.dataRoot, options.workspaceId, options.workspaceRevision),
|
||||
installationOverlay: overlay,
|
||||
bindings,
|
||||
runtimePaths(options.dataRoot, options.workspaceId, options.workspaceRevision),
|
||||
context,
|
||||
overlay,
|
||||
options.semanticRuntime,
|
||||
),
|
||||
};
|
||||
bindingDigest: stableBindingDigest(bindings),
|
||||
semanticQdrantUrl: options.semanticRuntime.internalQdrantUrl,
|
||||
releaseSecrets: () => secretLease?.release(),
|
||||
renderedConfig: renderRuntimeConfig(
|
||||
options.workspace,
|
||||
bindings,
|
||||
runtimePaths(options.dataRoot, options.workspaceId, options.workspaceRevision),
|
||||
context,
|
||||
overlay,
|
||||
options.semanticRuntime,
|
||||
),
|
||||
};
|
||||
} catch (error) {
|
||||
secretLease?.release();
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
export function renderWorkspaceRuntimeFromSnapshotPath(options: {
|
||||
@@ -334,6 +353,7 @@ export function renderWorkspaceRuntimeFromSnapshotPath(options: {
|
||||
dataRoot: string;
|
||||
secretRoots: readonly string[];
|
||||
semanticRuntime: SemanticRuntimeConfig;
|
||||
workspaceSecretStore?: WorkspaceSecretStore;
|
||||
}): RenderedWorkspaceRuntime {
|
||||
const snapshot = readSnapshotWorkspace(options.snapshotPath);
|
||||
return renderWorkspaceRuntimeFromWorkspace({
|
||||
@@ -346,6 +366,7 @@ export function renderWorkspaceRuntimeFromSnapshotPath(options: {
|
||||
dataRoot: options.dataRoot,
|
||||
secretRoots: options.secretRoots,
|
||||
semanticRuntime: options.semanticRuntime,
|
||||
workspaceSecretStore: options.workspaceSecretStore,
|
||||
});
|
||||
}
|
||||
|
||||
@@ -358,6 +379,7 @@ export async function renderActiveWorkspaceRuntime(options: {
|
||||
dataRoot: string;
|
||||
secretRoots: readonly string[];
|
||||
semanticRuntime: SemanticRuntimeConfig;
|
||||
workspaceSecretStore?: WorkspaceSecretStore;
|
||||
}): Promise<ActiveRenderedWorkspaceRuntime> {
|
||||
// The persisted active state may reference host-side snapshot paths (written by another
|
||||
// process or installation). Read the active state directly and resolve the immutable snapshot
|
||||
@@ -387,6 +409,7 @@ export async function renderActiveWorkspaceRuntime(options: {
|
||||
dataRoot: options.dataRoot,
|
||||
secretRoots: options.secretRoots,
|
||||
semanticRuntime: options.semanticRuntime,
|
||||
workspaceSecretStore: options.workspaceSecretStore,
|
||||
});
|
||||
return {
|
||||
...rendered,
|
||||
@@ -584,4 +607,4 @@ export async function publishDeterministicRuntimeConfigLease(options: {
|
||||
inputFingerprint: inputFingerprintValue,
|
||||
release: () => undefined,
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user