Files
Philippe Martin b0b15d6e5a refactor(providers)!: declare imported profile behavior safely
Move non-secret environment defaults and discovery keys into bounded profile
declarations. Validate credential collisions and required platform adapters,
and keep profile revision encoding deterministic.

Preserve sandbox template and spec environment values, including empty values,
over non-secret profile defaults in both launch paths. Keep provider credential
placeholders authoritative. Allow identical non-secret values from attached
providers while rejecting conflicting values and credential key collisions.

Never expose GOOGLE_SERVICE_ACCOUNT_KEY through credentials or non-secret
defaults, including older stored profiles. Omit stale private-key records
without withholding remaining Vertex tokens or SDK configuration. Remove
ID-selected adapters and orphaned GCP metadata helpers; document migration
and compatible example imports.

Closes #3442

BREAKING CHANGE: Google Cloud and Vertex profiles must declare their
environment and discovery effects. The Google Cloud metadata profile requires
the currently unavailable gcp-metadata adapter. Configure Vertex private key
material through credential refresh instead of GOOGLE_SERVICE_ACCOUNT_KEY.

Signed-off-by: Philippe Martin <phmartin@redhat.com>
2026-10-02 18:41:19 +02:00
..