logicsrc/packages/schemas/schemas/logicsrc-credential-sync-plan.schema.json
Anthony Ettinger cf73fe5af2 feat(credential-sharing): implement the Credential Sharing OpenSpec (M1-M3)
New @logicsrc/plugin-credential-sharing: a provider-neutral secret-sync engine
with env/.env, Doppler, Railway, and GitHub Secrets adapters behind one
CredentialProvider contract.

- engine: inspect -> diff -> plan -> approve -> sync -> rollback -> audit/export
- dry-run is the default for sync; --approve writes; destructive changes gated
- fingerprint-based diffs (salted SHA-256); raw values never printed or stored in
  plans/runs/audit; rollback pre-image kept in a 0600 .logicsrc vault (gitignored)
- github-secrets is write-only for values (sealed-box via libsodium), so it cannot
  be a sync source or value-restoring rollback target
- CLI: real `logicsrc credentials <providers|inspect|diff|plan|approve|sync|
  rollback|audit|export>` (replaces the prior stub)
- 4 JSON schemas registered in @logicsrc/validators
- flip logicsrc.com/credential-sharing band from coming-soon to available
- 37 tests pass; full env->env lifecycle verified; artifacts schema-validate

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 15:24:30 +00:00

56 lines
2 KiB
JSON

{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://schemas.logicsrc.com/logicsrc-credential-sync-plan.schema.json",
"title": "LogicSRC Credential Sync Plan",
"type": "object",
"required": ["type", "id", "from", "to", "policy", "changes", "requiresApproval", "createdAt"],
"additionalProperties": false,
"$defs": {
"endpoint": {
"type": "object",
"required": ["provider"],
"additionalProperties": false,
"properties": {
"provider": { "type": "string", "minLength": 1 },
"path": { "type": "string" },
"project": { "type": "string" },
"config": { "type": "string" },
"service": { "type": "string" },
"scope": { "type": "string" },
"metadata": { "type": "object" }
}
},
"change": {
"type": "object",
"required": ["key", "op", "destructive"],
"additionalProperties": false,
"properties": {
"key": { "type": "string", "minLength": 1 },
"op": { "enum": ["add", "update", "remove", "unchanged", "unknown"] },
"sourceFingerprint": { "type": "string" },
"targetFingerprint": { "type": "string" },
"destructive": { "type": "boolean" }
}
}
},
"properties": {
"type": { "const": "logicsrc.credential_sync_plan" },
"id": { "type": "string", "minLength": 1 },
"from": { "$ref": "#/$defs/endpoint" },
"to": { "$ref": "#/$defs/endpoint" },
"policy": {
"type": "object",
"required": ["redactValues", "requireApprovalForDestructive"],
"additionalProperties": false,
"properties": {
"redactValues": { "const": true },
"requireApprovalForDestructive": { "type": "boolean" },
"denyKeys": { "type": "array", "items": { "type": "string" } }
}
},
"changes": { "type": "array", "items": { "$ref": "#/$defs/change" } },
"requiresApproval": { "type": "boolean" },
"rollbackOfRunId": { "type": "string", "minLength": 1 },
"createdAt": { "type": "string", "format": "date-time" }
}
}