STANDUP.md section 0A, the prerequisite list handed to the maintainer before step 1, has this item:
Every publish credential and environment the repo's mechanisms declare in spec/secrets.json, including any environment a deploy gates on.
No mechanism in spec/secrets.json declares an environment, so a stand-up following this item finds nothing to provision for a deploy environment.
What the tree actually says
- Publish credentials: these come from the mechanisms in
spec/secrets.json, so that half of the item is right.
- Environment names: step 1 records them in the registry entry's
environments (name, branchPolicy, branches). repo-config/configure.sh check_environments checks that each one exists and carries its branch policy.
- Secret and variable names inside an environment: neither
spec/secrets.json nor the registry lists them. deploy-ssh has requires: [] and stores: []. But the hub's .github/workflows/deploy-site-task.yml does fix them. It reads vars.SITE_BASE_URL, vars.DEPLOY_SSH_USER, vars.DEPLOY_SSH_HOST, vars.DEPLOY_SSH_KNOWN_HOSTS and vars.SITE_EXTRA_BASE_URL from the bound environment, and it declares DEPLOY_SSH_PRIVATE_KEY and the SITE_AUTH_TOKEN and SITE_EXTRA_AUTH_TOKEN pairs as secrets. So the maintainer supplies the values, under the names that task reads.
Why this was split out
The fix for #2268 tried to correct this item in the same change. Two rewrites each drew a new false claim under local review. The first said no hub file declares environment names, but the registry does. The second said no hub file declares the secret and variable names, but deploy-site-task.yml does. Rather than keep iterating, the item stayed at its develop wording. A fix should probably name all three sources: the mechanisms for credentials, step 1's registry environments for environment names, and the deploy task for the names each environment must hold. #2070, one declared source for environment-scope names, would change the third.
🤖 Generated with Claude Code
STANDUP.mdsection 0A, the prerequisite list handed to the maintainer before step 1, has this item:No mechanism in
spec/secrets.jsondeclares an environment, so a stand-up following this item finds nothing to provision for a deploy environment.What the tree actually says
spec/secrets.json, so that half of the item is right.environments(name, branchPolicy, branches).repo-config/configure.sh check_environmentschecks that each one exists and carries its branch policy.spec/secrets.jsonnor the registry lists them.deploy-sshhasrequires: []andstores: []. But the hub's.github/workflows/deploy-site-task.ymldoes fix them. It readsvars.SITE_BASE_URL,vars.DEPLOY_SSH_USER,vars.DEPLOY_SSH_HOST,vars.DEPLOY_SSH_KNOWN_HOSTSandvars.SITE_EXTRA_BASE_URLfrom the bound environment, and it declaresDEPLOY_SSH_PRIVATE_KEYand theSITE_AUTH_TOKENandSITE_EXTRA_AUTH_TOKENpairs as secrets. So the maintainer supplies the values, under the names that task reads.Why this was split out
The fix for #2268 tried to correct this item in the same change. Two rewrites each drew a new false claim under local review. The first said no hub file declares environment names, but the registry does. The second said no hub file declares the secret and variable names, but
deploy-site-task.ymldoes. Rather than keep iterating, the item stayed at its develop wording. A fix should probably name all three sources: the mechanisms for credentials, step 1's registryenvironmentsfor environment names, and the deploy task for the names each environment must hold. #2070, one declared source for environment-scope names, would change the third.🤖 Generated with Claude Code