fabro/docs/internal/product
Bryan Helmkamp 671324a06f
docs(secrets): document settings-declared credentials, fix stale local-run guidance
server-secrets-strategy.md described only two credential mechanisms — bootstrap
ServerSecrets and vault-only optional integrations — and stated its most
restrictive rule in terms of "server runtime", which is ambiguous now that every
run is a server process plus a worker. It omitted the third mechanism actually
used by operator-configured integrations: settings-declared credentials in
InterpString fields, resolved at consumption time from {{ env.NAME }} or
{{ secrets.NAME }}, as LLM provider extra_headers already does.

Add a "Which process resolves what" table keyed on resolving process and timing,
a "Settings-declared credentials" section with the extra_headers precedent, and a
mechanism table at the head of "Adding A New Server Secret". Replace "server
runtime" with per-process statements, and describe where CredentialResolver's
process-env fallback is actually live.

Also correct six docs that told operators to export provider keys for "standalone
local runs". There is no CLI-local run execution: runs always execute in a worker
whose environment is cleared and repopulated from WORKER_ENV_ALLOWLIST, which
excludes provider API keys. Those instructions could not have worked.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-25 09:04:59 -04:00
..
business-problem.md refactor(workflow): remove retro stage (#230) 2026-05-09 10:18:20 -04:00
current-state.md refactor(workflow): remove retro stage (#230) 2026-05-09 10:18:20 -04:00
personas.md refactor(docs): split docs/ into public/ and internal/ 2026-04-27 07:21:13 -07:00
product-description.md refactor(workflow): remove retro stage (#230) 2026-05-09 10:18:20 -04:00
success-metrics.md refactor(workflow): remove retro stage (#230) 2026-05-09 10:18:20 -04:00
technical-requirements.md docs(secrets): document settings-declared credentials, fix stale local-run guidance 2026-07-25 09:04:59 -04:00