Correct the False No-Vocabulary Claims About Environment Secrets - #2271
Conversation
spec/secrets.json said it had no vocabulary for per-environment secrets and that a repo declares them in its own environments block, while spec/secrets.schema.json defines an environments block and the file carries none. spec/project-types.json and docs/reusable-workflows.md repeated the first claim. All four now say what holds: the schema allows such a block, this file carries none, and no tool here checks environment-scoped secrets. Refs #2268 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The strict review found the first wording hid the gap the old claim pointed at: the schema's environments block has no per-repo dimension, and downstream copies of spec/secrets.json are retired, so no repository can declare its environment names there. The secrets.json note now says so, environmentSecrets is described as a field of that block, project-types.json gives the real reason requiredSecrets leaves the names out, the reusable-workflows paragraph separates the checked environment boundary from its unchecked secrets, TODO.md's settled entry stops saying a repo may declare them, and the note's one semicolon is recast. Refs #2268 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
STANDUP.md's prerequisite list said spec/secrets.json mechanisms declare a deploy's environments, which none does. It now names the mechanisms for publish credentials, the registry entry's environments for environments, and says no hub file declares the environment secret names, so the maintainer supplies them. Refs #2268 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The strict review found the checklist item claiming no hub file declares the environment names, which the registry does, and pointing at a registry entry that does not exist yet when the list is handed over. It now asks for every environment a deploy gates on, which step 1 records in the registry, and says no hub file declares the secret and variable names an environment holds. Refs #2268 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Two rewrites of the stand-up prerequisite item each drew a new false claim under review, the second about the environment secret and variable names the hub's deploy-site-task.yml fixes. Per the stop rule this change set for itself, the item returns to its develop wording and is filed as its own issue, leaving this change the four statements that verified true. Refs #2268 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: ptr727/ProjectTemplate/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #2271 +/- ##
========================================
Coverage 57.31% 57.31%
========================================
Files 16 16
Lines 7611 7611
========================================
Hits 4362 4362
Misses 3249 3249
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Documentation wording and sentence-length issues remain unresolved, including an inaccurate workflow claim.
Review effort: Lite
Findings: 1
What changed in this PR
Corrects inaccurate documentation about environment-scoped secrets and clarifies audit and configuration boundaries.
Changes:
- Clarifies schema and repository limitations.
- Updates secret and project-type guidance.
- Revises reusable workflow documentation and TODO notes.
| File | Summary |
|---|---|
TODO.md |
Corrects environment-secret guidance. |
spec/secrets.json |
Clarifies schema support and limitations. |
spec/project-types.json |
Updates credential requirements guidance. |
docs/reusable-workflows.md |
Clarifies environment-secret handling. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Copilot found "no hub tool checks the secrets an environment holds" false, since deploy-site-task.yml fails its run when a value it needs is missing or empty. The reusable-workflows paragraph and the hugo type note now say no audit or configuration tool inventories those secrets, and name the deploy task's runtime check as the one place an empty value is caught. Refs #2268 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The deploy task fails its run on an empty required value and passes an empty optional one, so the hugo type note now says "an empty one it needs". Refs #2268 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Refs #2268
Summary
The hub's own prose said
spec/secrets.jsonhas no vocabulary for per-environment secrets, and that a repo declares them in its ownenvironmentsblock. Both claims are false. They are also how Blog's registry note went wrong (#2269). The real gap is different: the schema'senvironmentsblock has no per-repo dimension, and downstream copies ofspec/secrets.jsonare retired (spec/divergences.json), so no repository can declare its environment secret names there.spec/secrets.jsontop noteenvironmentsblock, whoseenvironmentSecretsmap lives inside it, but it has no per-repo place, so this file carries none, and no tool would read onespec/secrets.jsondeploy-sshenvironmentsblockspec/project-types.jsonrequiredSecretsbecause the audit would look for them in the repository storedocs/reusable-workflows.mdspec/secrets.jsondeclares none of the deploy secrets, and no hub tool checks the secrets an environment holds. The environment boundary's own branch policy is checked elsewhereTODO.mdThe edited note's one semicolon is also recast.
STANDUP.mdmakes the same claim in its prerequisite list. Two rewrites of it each drew a new false claim under review, so it stays at its develop wording, and #2270 tracks it.Verification
local-strict-review: across four passes, each changed sentence was checked againstspec/secrets.schema.json,spec/divergences.json,docs/repo-config.md,spec/audit.py,spec/validate.pyandrepo-config/configure.sh. The four statements here verified true. The one finding left,STANDUP.md, is filed as Fix STANDUP.md's Prerequisite Item That Says Mechanisms Declare Environments #2270, and the receipt is recorded.spec/validate.py,prose_lint --diff origin/develop, anddocker_lint.pyare all clean. The fullunittest discoverrun passes.🤖 Generated with Claude Code