docs(FN-4799): complete Step 2 — update AGENTS secrets guidance
Fusion-Task-Id: FN-4799 Fusion-Task-Lineage: 20398bff-8ec8-49cb-8b15-de874c5f731f
This commit is contained in:
committed by
gsxdsm
parent
8ae5b86132
commit
82e6c507cd
22
AGENTS.md
22
AGENTS.md
@@ -293,8 +293,11 @@ Fusion has a Node Dashboard view for managing mesh network nodes. See [docs/arch
|
||||
| POST | `/api/nodes/:id/settings/pull` | Pull settings from a remote node |
|
||||
| GET | `/api/nodes/:id/settings/sync-status` | Get sync status and diff summary |
|
||||
| POST | `/api/nodes/:id/auth/sync` | Sync model auth credentials |
|
||||
| POST | `/api/nodes/:id/secrets/push` | Push local secrets snapshot to a remote node *(planned; follow-up FN-4867)* |
|
||||
| POST | `/api/nodes/:id/secrets/pull` | Pull remote secrets snapshot into local node *(planned; follow-up FN-4867)* |
|
||||
| POST | `/api/settings/sync-receive` | Receive pushed settings (inbound) |
|
||||
| POST | `/api/settings/auth-receive` | Receive auth credentials (inbound) |
|
||||
| POST | `/api/secrets/sync-receive` | Receive pushed secrets payload (inbound) *(planned; follow-up FN-4867)* |
|
||||
| GET | `/api/settings/auth-export` | Export local auth credentials |
|
||||
|
||||
All remote node endpoints require the target node to have an `apiKey` configured. Inbound endpoints validate the `Authorization: Bearer <apiKey>` header against the local node's apiKey.
|
||||
@@ -323,6 +326,14 @@ Use `fn_web_fetch` for lightweight URL reads from agent/chat sessions. It perfor
|
||||
- Scope: read-only fetch (no JS rendering, no auth flows, no POST/cookie workflows)
|
||||
- Use `agent-browser` skill when pages require JavaScript execution, interactive navigation, or richer browser behavior
|
||||
|
||||
### `fn_secret_get`
|
||||
|
||||
`fn_secret_get` is planned as the agent-facing secret-read tool, but it is not shipped in `packages/cli/src/extension.ts` yet in this branch.
|
||||
|
||||
- Status: pending follow-up **FN-4867**
|
||||
- Do not assume parameters/response contract until implementation lands
|
||||
- Use [docs/secrets.md](./docs/secrets.md) for current shipped capabilities and pending integration status
|
||||
|
||||
## Agent Spawning (`spawn_agent` tool)
|
||||
|
||||
The executor agent can spawn child agents that run in parallel. Each spawned agent:
|
||||
@@ -571,6 +582,17 @@ The `fn serve` command starts Fusion as a headless node (API server + AI engine,
|
||||
|
||||
See [docs/architecture.md](./docs/architecture.md) for the full reference including health endpoint and startup banner.
|
||||
|
||||
## Secrets
|
||||
|
||||
Fusion includes encrypted secret storage in project (`.fusion/fusion.db` → `secrets`) and global (`~/.fusion/fusion-central.db` → `secrets_global`) scopes.
|
||||
|
||||
- Encryption: AES-256-GCM ciphertext + nonce storage; plaintext is not persisted
|
||||
- Per-secret access policy metadata: `auto` | `prompt` | `deny`
|
||||
- Policy default: `secretsAccessPolicy` with resolution `row → global default → "prompt"`
|
||||
- Master key today is provided through the core `MasterKeyProvider` abstraction
|
||||
|
||||
See [docs/secrets.md](./docs/secrets.md) for implementation details and current availability gaps (FN-4867: tool/sync/env materialization wiring).
|
||||
|
||||
## Settings
|
||||
|
||||
fn uses a two-tier settings hierarchy:
|
||||
|
||||
Reference in New Issue
Block a user