feat(FN-4792): complete Step 6 — finalize delivery and changeset
Fusion-Task-Id: FN-4792 Fusion-Task-Lineage: 8e29f9a0-4c9f-4322-9595-3c9c581dacb0
This commit is contained in:
committed by
gsxdsm
parent
9327da718f
commit
f0df7cb1d2
5
.changeset/FN-4792-secret-access-policy.md
Normal file
5
.changeset/FN-4792-secret-access-policy.md
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
"@runfusion/fusion": patch
|
||||||
|
---
|
||||||
|
|
||||||
|
Internal: introduce `SecretAccessPolicy` vocabulary (`auto`/`prompt`/`deny`) and `resolveSecretAccessPolicy()` resolver plus a global `secretsAccessPolicy` default setting. Foundation for the upcoming secrets subsystem; no user-visible behavior yet.
|
||||||
@@ -2100,6 +2100,11 @@ export interface GlobalSettings {
|
|||||||
ntfyDashboardHost?: string;
|
ntfyDashboardHost?: string;
|
||||||
/** Optional global fallback per-task token budget defaults. */
|
/** Optional global fallback per-task token budget defaults. */
|
||||||
taskTokenBudget?: TaskTokenBudget;
|
taskTokenBudget?: TaskTokenBudget;
|
||||||
|
/** Default access policy applied to a secret when its row-level `access_policy`
|
||||||
|
* is null/unset. One of "auto" (return value to caller and audit),
|
||||||
|
* "prompt" (route through approvals), or "deny" (reject without prompt).
|
||||||
|
* Default when unset: "prompt". */
|
||||||
|
secretsAccessPolicy?: SecretAccessPolicy;
|
||||||
/** Policy for recovering tasks whose existing owning node becomes unavailable. */
|
/** Policy for recovering tasks whose existing owning node becomes unavailable. */
|
||||||
owningNodeHandoffPolicy?: OwningNodeHandoffPolicy;
|
owningNodeHandoffPolicy?: OwningNodeHandoffPolicy;
|
||||||
/** How long a task must remain in `status='failed'` before a push notification fires.
|
/** How long a task must remain in `status='failed'` before a push notification fires.
|
||||||
@@ -2807,11 +2812,6 @@ export interface ProjectSettings {
|
|||||||
* to permanent executor agents using the reporting chain heuristic.
|
* to permanent executor agents using the reporting chain heuristic.
|
||||||
* Tasks without an eligible permanent executor remain queued. */
|
* Tasks without an eligible permanent executor remain queued. */
|
||||||
ephemeralAgentsEnabled?: boolean;
|
ephemeralAgentsEnabled?: boolean;
|
||||||
/** Default access policy applied to a secret when its row-level `access_policy`
|
|
||||||
* is null/unset. One of "auto" (return value to caller and audit),
|
|
||||||
* "prompt" (route through approvals), or "deny" (reject without prompt).
|
|
||||||
* Default when unset: "prompt". */
|
|
||||||
secretsAccessPolicy?: SecretAccessPolicy;
|
|
||||||
/** Approval policy for agent provisioning tools (fn_agent_create/fn_agent_delete). */
|
/** Approval policy for agent provisioning tools (fn_agent_create/fn_agent_delete). */
|
||||||
agentProvisioning?: {
|
agentProvisioning?: {
|
||||||
approvalMode?: AgentProvisioningApprovalMode;
|
approvalMode?: AgentProvisioningApprovalMode;
|
||||||
|
|||||||
Reference in New Issue
Block a user