Manual configuration markers for external resource secrets
Summary
- Implemented OpenSpec 6.3 on branch
codex/octopus-import-external-secret-shells. - Added import-only manual configuration markers and shell mapping for Feed, Account, Certificate, and Target resources in OctopusImportManualConfigurationMarker.cs and OctopusImportExternalResourceShellMapper.cs.
- Extended Feed mapping so credentials remain omitted, safe manual configuration marker properties are added, and markers are returned from mapping results.
- Extended preview planning so Feed/Account/Certificate/Target secret omissions emit redacted manual-configuration diagnostics without changing public import DTO contracts.
- Added focused tests for feed markers, account empty credential shells, certificate manual shells, target endpoint secret omission, preview diagnostics, and non-leakage.
- Updated
SESSION_MEMORY.mdand marked OpenSpec task6.3complete; did not implement 6.2, 6.4, 6.5, 6.6, or confirmation orchestration.
Test plan
-
dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter "FullyQualifiedName~OctopusImportFeedMapperTests|FullyQualifiedName~OctopusImportExternalResourceShellMapperTests|FullyQualifiedName~OctopusImportPreviewPlannerTests|FullyQualifiedName~OctopusImportRedactionTests" --no-restorepassed 30/30. -
dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~Services.OctopusImport --no-restore -p:UseSharedCompilation=false -m:1 -v quietpassed 222/222. -
git diff --checkpassed.