mirror of
https://github.com/agent-substrate/substrate.git
synced 2026-10-02 03:24:42 +08:00
Adds a credential provider for egress credential injection backed by Google Cloud Secret Manager. **It lives in its own Go module under `plugins/gcp-secret-manager`, temporally hosted here until it moves to a repository of its own.** **What it does** - Serves `credproviderpb.CredentialProvider` over mTLS and admits only the egress gateway's identity (`--injector-identity`). - Resolves global and regional secrets, optionally picking one key out of a JSON payload: `ate-secret://secretmanager.googleapis.com/projects/<project>[/locations/<location>]/secrets/<secret>/versions/<version>[/keys/<key>]` - Enforces a default-deny atespace→project policy (`--project-policy-file`), the counterpart of the Kubernetes provider's namespace policy. - Returns a retryable 503 only for transient Secret Manager failures, and caps each read with `--fetch-timeout` (default 3s). **Repository changes** - New top-level `plugins/` directory for self-contained plugins, documented in `docs/dev/code-layout.md` and `AGENTS.md`. The module imports only substrate's public `pkg/` packages; a test enforces this. - CI runs the module's tests, `make verify` and golangci-lint. govulncheck scans the module too, with the action pinned by SHA. - `docs/egress-credential-injection.md` describes each provider's credential URI format. The plugin's README covers installing and using it. - [ ] Tests pass - [ ] Appropriate changes to documentation are included in the PR