Skip to content

feat(config): ${env:NAME} placeholders in plugin config; ADR 0003 - #111

Merged
gusfcarvalho merged 1 commit into
lisa/agent-config-10-apply-overlaysfrom
lisa/agent-config-11-env-placeholders
Oct 6, 2026
Merged

gusfcarvalho merged 1 commit into
lisa/agent-config-10-apply-overlaysfrom
lisa/agent-config-11-env-placeholders

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Part 11/11 of the split of #95 (agent remote configuration) into a stack. Review it as the diff against its base branch.

  • plugins..config values may reference environment variables, whole or
    embedded (R24), in the file and in an overlay. Reports, redaction and the
    digest keep the unresolved placeholder, so rotating a secret changes
    none of them. CCF_API_AUTH_
    may never be referenced.
  • An unset variable the file references is a warning and the literal
    reaches the plugin unchanged, exactly as on main (R60). One an overlay
    introduces fails the revision with env-missing; the error names the
    variable, never a value.
  • ADR 0003 records the remote configuration overlay design; README points
    to it and to the state directory settings.

Size: 368 lines changed (go.mod/go.sum excluded). Builds, vets, is gofmt-clean and passes go test -race ./... on its own; the top of the stack is byte-identical to #95 merged with main.

Stack
  1. test: pin agent configuration hashes and evidence seeds #101 test: pin agent configuration hashes and evidence seeds
  2. feat(runner): policy source from the _policy_path label; extra evidence props #102 feat(runner): policy source from the _policy_path label; extra evidence props
  3. refactor(config): adopt api/pkg/agentconfig as the declared config #103 refactor(config): adopt api/pkg/agentconfig as the declared config
  4. feat(agent): stable instance ID and per-instance state directory #104 feat(agent): stable instance ID and per-instance state directory
  5. feat(agent): AgentRunner primitives for prepare-then-cancel reloads #105 feat(agent): AgentRunner primitives for prepare-then-cancel reloads
  6. feat(agent): prepare-then-cancel config file reloads #106 feat(agent): prepare-then-cancel config file reloads
  7. feat(pluginlib): read the agent library version a plugin binary was built with #107 feat(pluginlib): read the agent library version a plugin binary was built with
  8. feat(agent): report the configuration to the API (remote_config off/report) #108 feat(agent): report the configuration to the API (remote_config off/report)
  9. feat(agentstate): persisted cache for the remote configuration overlay #109 feat(agentstate): persisted cache for the remote configuration overlay
  10. feat(agent): pull and apply remote configuration overlays (apply_safe/apply_all) #110 feat(agent): pull and apply remote configuration overlays (apply_safe/apply_all)
  11. 👉 feat(config): ${env:NAME} placeholders in plugin config; ADR 0003 #111 feat(config): ${env:NAME} placeholders in plugin config; ADR 0003

🤖 Generated with Claude Code

@ccf-lisa
ccf-lisa Bot added this pull request to stack #112 October 5, 2026 18:01
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 5e3e85a1-cc52-4f59-befb-cb37bc187528

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 112): #101 → #102 → #103 → #104 → #105 → #106 → #107 → #108 → #109 → #110 → #111

@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config-11-env-placeholders branch from 1729ce5 to e40cc99 Compare October 6, 2026 10:27
@ccf-lisa

ccf-lisa Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

PR approved. Marking ready for e2e.

- plugins.*.config values may reference environment variables, whole or
  embedded (R24), in the file and in an overlay. Reports, redaction and the
  digest keep the unresolved placeholder, so rotating a secret changes
  none of them. CCF_API_AUTH_* may never be referenced.
- An unset variable the file references is a warning and the literal
  reaches the plugin unchanged, exactly as on main (R60). One an overlay
  introduces fails the revision with env-missing; the error names the
  variable, never a value.
- ADR 0003 records the remote configuration overlay design; README points
  to it and to the state directory settings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config-11-env-placeholders branch from e40cc99 to 715c268 Compare October 6, 2026 15:59
@gusfcarvalho
gusfcarvalho merged commit f547e3d into main Oct 6, 2026
9 checks passed
@gusfcarvalho
gusfcarvalho deleted the lisa/agent-config-11-env-placeholders branch October 6, 2026 16:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant