Replies: 3 comments 2 replies
|
Strong proposal - this is the observability gap behind a whole family of "why is my key ignored" threads (#71/#190/#981), and it fits the We already ship the env-diagnostics side in dsh-plugin-doctor (the Answers to the open questions
Security boundaryAgree 100%: never print the raw value, prefix/suffix, hash, or length. Only key name + source + state + non-sensitive reason. The Happy to implement a reference |
|
Done - a reference implementation is now live in dsh-plugin-doctor v1.13.0. What shippednpx dsh-plugin-doctor env explain DEEPSEEK_API_KEY
npx dsh-plugin-doctor env explain MY_KEY --jsonLayer model (matches the #981 framing): JSON envelope (exactly the contract from the proposal): {
"key": "DEEPSEEK_API_KEY",
"resolved": true,
"source": "launch environment",
"layers": [
{ "layer": "launch environment", "state": "selected", "reason": "selected (highest precedence)" },
{ "layer": "project .env", "state": "lower-precedence", "reason": "present but shadowed" },
{ "layer": "user .env", "state": "lower-precedence", "reason": "present but lower precedence" }
],
"value": "[redacted]"
}Security boundary enforced in code: the raw value never enters any output, error message, or log line - the Vocabulary note
Open questions 1-3 answered in the implementation: empty = report + continue (never mask), one Repo: https://github.com/zoahdev/dsh-plugin-doctor (v1.13.0, tests 40/40 + dsh-doctor/v1 contract check green). |
|
Done on both asks - implementation and a written spec are live:
Both follow your constraints: read-only, value-independent, constant The spec also marks |
Uh oh!
There was an error while loading. Please reload this page.
Motivation
DeepSeek Harness resolves environment variables from multiple layers and applies additional rules such as bootstrap-only filtering. When configuration fails, users currently have no safe way to determine which layer won or why a value was ignored.
Several discussions expose different sides of the same observability gap:
.envpath is surfaced as a loader warning..envabort startup.The
dsh doctorproposal in #1719 focuses on broad runtime and dependency health. This proposal is narrower: explain the resolution of one environment key without exposing its value.Proposal
Add a read-only CLI command (name illustrative):
dsh env explain DEEPSEEK_API_KEY --profile webExample output:
The command could report states such as:
selectedabsentemptyrejected-protectednon-regular-pathunreadablelower-precedenceA
--jsonmode would make the result usable by diagnostic tools and support workflows.Security requirements
The command should never print or derive secret material. In particular, it should not expose:
Only the key name, source layer, resolution state, and non-sensitive reason should be returned.
Open questions
dsh env explaincommand, part ofdsh doctor, or an internal API consumed by both?Would this kind of secret-safe provenance view fit the intended configuration model?
All reactions