test(proxy): classify the federation params in the credential slot registry

main's registry test (#43298) now fails the build for any credential-named
deployment param without a classification. The five federation fields that
carry a token, a token file path, or a signing or client secret reference are
Unplanted, matching WIF_SECRET_BEARING_KEYS; the four remaining Keycloak
settings name a URL, a client id, an auth method, or a scope and are NotSecret
This commit is contained in:
mateo-berri 2026-10-02 21:10:21 -07:00
parent f4d61c3713
commit 9e97756239

View file

@ -124,6 +124,15 @@ DEPLOYMENT_PARAM_CLASSIFICATION: Final[Mapping[str, Classification]] = MappingPr
"default_api_key_tpm_limit": NotSecret("rate limit number"),
"default_api_key_rpm_limit": NotSecret("rate limit number"),
"valkey_password": Unplanted(),
"anthropic_identity_token": Unplanted(),
"anthropic_identity_token_file": Unplanted(),
"anthropic_issuer_signing_key_ref": Unplanted(),
"anthropic_keycloak_token_url": NotSecret("Keycloak token endpoint URL"),
"anthropic_keycloak_client_id": NotSecret("Keycloak client identifier"),
"anthropic_keycloak_auth_method": NotSecret("name of the client authentication method"),
"anthropic_keycloak_client_secret_ref": Unplanted(),
"anthropic_keycloak_scope": NotSecret("OAuth scope string"),
"openai_identity_token_file": Unplanted(),
}
)