Skip to content

feat: expose metadata-only project environment resolution - #153

Merged
roodboi merged 1 commit into
nextfrom
feat/env-metadata-planning
Oct 7, 2026
Merged

roodboi merged 1 commit into
nextfrom
feat/env-metadata-planning

Conversation

@roodboi

@roodboi roodboi commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Planning code needs environment key names, winning scopes and secret flags without loading decryption keys or exposing stored values. resolveProjectEnvMetadata now provides that metadata through the existing project-env owner. The runtime resolver shares the extracted target-scope projection, preserving layer precedence, tombstones, host/service collisions and unknown-scope behavior.

The new API returns only selection/file paths, scope names and per-target metadata; it never returns plaintext, ciphertext or raw/merged layers. Missing modern configuration remains null for callers to handle their existing legacy fallback. Metadata reads refuse failed reads, dangling links and non-file inputs with a value-free error; existing runtime reads and diagnostics retain their behavior. Readable symlinks remain supported.

Validation:

  • 50 focused environment tests pass across metadata, runtime config, local inheritance and worktree key suites.
  • Synthetic invalid encrypted entries resolve without keys or decryption. Key-path read failure controls, output/error non-disclosure, selected/default/null overlays, primary/local inheritance, removals/reintroduction, host collisions and unknown scopes are covered.
  • Final pinned Bun 1.4.2 typecheck, lint and full tests pass. CLI tasks executed fresh: 2,100 tests passed, 68 skipped, 0 failed. The unchanged DB task reused its valid cache (2 tests passed). Explicit changed-source/test lint and staged privacy checks pass. Frozen install made no dependency or lockfile changes.
  • Independent review approved the final source, tests and docs. No VM or application runtime changes were required.

Release signal: feat for a repository API; no CLI interface or execution behavior change. This is a prerequisite for metadata planning, not a completed native configuration compiler. Paths and names remain private project metadata; the API is not portable plan serialization or an atomic input/admission fence, and does not prove encrypted values can be decrypted.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@roodboi
roodboi merged commit b1b281f into next Oct 7, 2026
9 checks passed
@roodboi
roodboi deleted the feat/env-metadata-planning branch October 7, 2026 03:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant