Files
Shiju cf79135a23 fix(providers): integrate stable placeholders with current main
Preserve provider readiness and managed files while adapting stable
credential delivery to the current supervisor and workspace APIs. Keep
protobuf field assignments compatible with upstream.

Exercise one persistent caller-assertion client across external rotation,
with an ordinary-reference control and verified HTTPS denial cases.

Signed-off-by: Shiju <shiju@nvidia.com>
2026-10-01 22:49:05 +05:30
..

openshell-providers

Provider discovery and normalization for credentials that sandboxes need at runtime.

The gateway persists provider records. The sandbox supervisor fetches resolved provider environment from the gateway and injects credentials into agent child processes. This crate keeps provider-specific discovery and normalization logic out of the CLI and gateway control flow.

Responsibilities

  • Discover local credentials from environment variables and known config files.
  • Normalize discovered data into provider records.
  • Keep provider-specific parsing rules in provider modules.
  • Avoid logging credential values.

Non-Responsibilities

  • Persisting provider records.
  • Authorizing provider CRUD operations.
  • Injecting credentials into sandbox child processes.
  • Routing inference requests.

Those are owned by the gateway, sandbox supervisor, and router.

Security Notes

Provider data often contains API keys, bearer tokens, or local account configuration. Discovery code should return structured values without printing or tracing secrets. Callers that display provider data must redact sensitive fields by default.