Repository navigation
plat 489
github-actions[bot] edited this page Oct 6, 2026
·
1 revision
| Field | Value |
|---|---|
| State | fixed on main |
| Priority | - |
| Product | vault |
| Area | security-sandbox |
| Summary | fixed on main: the local launcher starts Vault in platform mode and wires the backend to it. |
| Coordination | Value |
|---|---|
| State | fixed on main; needs a local restart. Not yet checked against the owner's real workflows |
| Date | 2026-10-05 |
| Owner | security-sandbox |
Local runs started the gateway in standalone mode but never pointed the backend at it, so CAPLAYER_SERVICE_URL
was unset and the backend ran with no Vault: nothing checked grants, and the Vault secret-selection migration
never ran. Two LinkedIn schedules failed on 2026-10-04/05 because IMGBB_API_KEY and VERTEX_API_KEY were
selected but have no value anywhere; the owner wants Vault on locally by default.
-
run_server_with_logging.shstarts the gateway in platform mode (private service token undermcp-gateway/var/platform/, outside the docs) and exportsCAPLAYER_SERVICE_URL/CAPLAYER_SERVICE_TOKEN_FILEto the backend, like the server deploy.AGENTWORKS_LOCAL_VAULT=0turns it off. If the gateway fails to start the Vault URL is dropped, so the backend does not fail closed against nothing. - Checked on an isolated stack (own ports, docs and state): gateway healthy in platform mode, backend up and ran the secret-selection migration, no Vault errors in the log.
- Restart the local app, then run the migration dry run and list the selections with no value
(
IMGBB_API_KEY,VERTEX_API_KEYon both LinkedIn workflows); add the values or detach them. - The local gateway now starts with an empty platform state. Check the Platform group grants (PLAT-471) cover every existing workflow and MCP, and that a scheduled run still passes.
- Decide whether a missing secret should stop a whole run or only the step that needs it.
PLAT-489, fixed on main: the local launcher starts Vault in platform mode and wires the backend to it. Left: restart, then clean up selections with no value and check grants.
Auto-synced from docs/ on main. Edit there, not here.