Skip to content

Correct the False No-Vocabulary Claims About Environment Secrets - #2271

Merged
ptr727 merged 7 commits into
developfrom
feature/env-secret-wording
Oct 2, 2026
Merged

ptr727 merged 7 commits into
developfrom
feature/env-secret-wording

Conversation

@ptr727

@ptr727 ptr727 commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Refs #2268

Summary

The hub's own prose said spec/secrets.json has no vocabulary for per-environment secrets, and that a repo declares them in its own environments block. Both claims are false. They are also how Blog's registry note went wrong (#2269). The real gap is different: the schema's environments block has no per-repo dimension, and downstream copies of spec/secrets.json are retired (spec/divergences.json), so no repository can declare its environment secret names there.

File Now says
spec/secrets.json top note The schema still allows an environments block, whose environmentSecrets map lives inside it, but it has no per-repo place, so this file carries none, and no tool would read one
spec/secrets.json deploy-ssh Drops the "no vocabulary" claim and the pointer to a repo's own environments block
spec/project-types.json No tool here checks these credentials. A repo leaves them out of requiredSecrets because the audit would look for them in the repository store
docs/reusable-workflows.md spec/secrets.json declares none of the deploy secrets, and no hub tool checks the secrets an environment holds. The environment boundary's own branch policy is checked elsewhere
TODO.md The settled entry stops saying a repo may declare its environment names there

The edited note's one semicolon is also recast.

STANDUP.md makes the same claim in its prerequisite list. Two rewrites of it each drew a new false claim under review, so it stays at its develop wording, and #2270 tracks it.

Verification

  • local-strict-review: across four passes, each changed sentence was checked against spec/secrets.schema.json, spec/divergences.json, docs/repo-config.md, spec/audit.py, spec/validate.py and repo-config/configure.sh. The four statements here verified true. The one finding left, STANDUP.md, is filed as Fix STANDUP.md's Prerequisite Item That Says Mechanisms Declare Environments #2270, and the receipt is recorded.
  • spec/validate.py, prose_lint --diff origin/develop, and docker_lint.py are all clean. The full unittest discover run passes.

🤖 Generated with Claude Code

ptr727 and others added 5 commits October 1, 2026 18:23
spec/secrets.json said it had no vocabulary for per-environment secrets and
that a repo declares them in its own environments block, while
spec/secrets.schema.json defines an environments block and the file carries
none. spec/project-types.json and docs/reusable-workflows.md repeated the
first claim. All four now say what holds: the schema allows such a block,
this file carries none, and no tool here checks environment-scoped secrets.

Refs #2268

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The strict review found the first wording hid the gap the old claim pointed
at: the schema's environments block has no per-repo dimension, and
downstream copies of spec/secrets.json are retired, so no repository can
declare its environment names there. The secrets.json note now says so,
environmentSecrets is described as a field of that block, project-types.json
gives the real reason requiredSecrets leaves the names out, the
reusable-workflows paragraph separates the checked environment boundary
from its unchecked secrets, TODO.md's settled entry stops saying a repo may
declare them, and the note's one semicolon is recast.

Refs #2268

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
STANDUP.md's prerequisite list said spec/secrets.json mechanisms declare a
deploy's environments, which none does. It now names the mechanisms for
publish credentials, the registry entry's environments for environments,
and says no hub file declares the environment secret names, so the
maintainer supplies them.

Refs #2268

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The strict review found the checklist item claiming no hub file declares
the environment names, which the registry does, and pointing at a registry
entry that does not exist yet when the list is handed over. It now asks for
every environment a deploy gates on, which step 1 records in the registry,
and says no hub file declares the secret and variable names an environment
holds.

Refs #2268

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Two rewrites of the stand-up prerequisite item each drew a new false claim
under review, the second about the environment secret and variable names
the hub's deploy-site-task.yml fixes. Per the stop rule this change set for
itself, the item returns to its develop wording and is filed as its own
issue, leaving this change the four statements that verified true.

Refs #2268

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 01:39
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: ptr727/ProjectTemplate/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: f1fd220c-a2cb-427b-948e-ad85c657284e

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 57.31%. Comparing base (73b9f77) to head (90a7b77).

Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #2271   +/-   ##
========================================
  Coverage    57.31%   57.31%           
========================================
  Files           16       16           
  Lines         7611     7611           
========================================
  Hits          4362     4362           
  Misses        3249     3249           
Flag Coverage Δ
python-3.13 57.31% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Documentation wording and sentence-length issues remain unresolved, including an inaccurate workflow claim.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

Corrects inaccurate documentation about environment-scoped secrets and clarifies audit and configuration boundaries.

Changes:

  • Clarifies schema and repository limitations.
  • Updates secret and project-type guidance.
  • Revises reusable workflow documentation and TODO notes.
File Summary
TODO.md Corrects environment-secret guidance.
spec/​secrets.json Clarifies schema support and limitations.
spec/​project-types.json Updates credential requirements guidance.
docs/​reusable-workflows.md Clarifies environment-secret handling.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/reusable-workflows.md Outdated
ptr727 and others added 2 commits October 1, 2026 18:43
Copilot found "no hub tool checks the secrets an environment holds" false,
since deploy-site-task.yml fails its run when a value it needs is missing or
empty. The reusable-workflows paragraph and the hugo type note now say no
audit or configuration tool inventories those secrets, and name the deploy
task's runtime check as the one place an empty value is caught.

Refs #2268

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The deploy task fails its run on an empty required value and passes an empty
optional one, so the hugo type note now says "an empty one it needs".

Refs #2268

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 01:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Outstanding prose and consistency comments remain unresolved.

Review effort: Lite
Findings: None

Resolved since last review (1)

@ptr727
ptr727 merged commit f92076e into develop Oct 2, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/env-secret-wording branch October 2, 2026 01:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants