Files
deepseek-harness/packages/credentials/credentials/README.zh.md
Yichen Jiang b0a2011d95 docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00

3.1 KiB
Raw Blame History

dsh-credentials

English | 中文

抽象凭据 seamctx.credentials)。一条准则,三个推论:

配置只携带对机密的引用,绝不携带机密本身。 settings 分节或 cordis.yml 条目写 apiKeyEnv: DEEPSEEK_API_KEY,引用背后的值归凭据 provider 所有。于是设置文档可以放心同步、放心渲染进配置界面;describe() 无需持有值就能回答「配置了吗、来自哪层、能否写入」;轮换机密不触碰任何配置文件。

消费方按操作解析。 resolve(ref) 在每个操作开始时调用LLM 适配器每次模型请求解析一次),绝不跨操作缓存——正是这次读取让改过的凭据无需重启任何插件就作用于下一次请求。

**空的存储值等于不存在。**处处如此:resolve 跳过它,describe 报告未配置。空白永远不会伪装成已配置的机密。

接口面

import type { Context } from 'cordis'
import { credentialRef } from '@deepseek-ai/dsh-credentials'

declare const ctx: Context

const ref = credentialRef('DEEPSEEK_API_KEY')            // POSIX shell identifier, branded
const hit = await ctx.credentials.resolve(ref)           // { value, source } | undefined
const info = await ctx.credentials.describe(ref)         // { configured, source?, writable } — never the value
await ctx.credentials.set(ref, 'sk-…')                   // rejects while a read-only source shadows the ref
await ctx.credentials.unset(ref)                         // no-op when absent; same shadowing rule

credentials/updated (ref) 在 provider 管理的来源发生已提交变更后触发——setunset 或在存储中观察到的外部编辑。进程环境变量的变化不可观测,永不触发。消费方不需要该事件(它们按操作重新解析);它服务于配置界面刷新「已配置」徽标。

set/unset 的遮蔽规则是刻意的响亮失败:当只读来源(本地 provider 中即活跃进程环境正在提供该引用时写入会表面成功而解析仍返回遮蔽值——seam 选择直接拒绝,并通过 describe().writable 让界面提前把该引用渲染为只读。

Providers

dsh-credentials-local 把活跃进程环境叠加在 $DSH_HOME/.env 文件之上。seam 形状为 keyring、辅助命令、KMS 后端的 provider 留好了位置;远端 settings provider 永远不必携带机密。

Model Experience

经由消费它的 LLM 适配器间接生效:解析出的值为适配器的提供方请求授权,每个模型可见面都归适配器所有。

KV Cache effect

无直接失效;凭据绝不进入请求前缀。

Known Limitations and Deferred Work

  • 不提供枚举——seam 只回答被问到的引用;配置界面从 settings schema 得知引用集合,list() 没有当前消费方。
  • 引用限定为环境变量形状——在有 provider 需要更丰富寻址前,保持单一扁平的 POSIX 标识符命名空间。
  • 进程环境变化不可见——不可能为其发事件;界面只能在自身导航时重新读取 describe()